CNN.Com, Politically Motivated DDoS, and Asymmetric Warfare

Apr 23, 2008 9:16 AM PST | Comments: 1
Print
By Jose Nazario
Jose Nazario

Once again I find myself thinking about the nature of the asymmetric warfare threat posed by politically motivated DDoS (Estonia in 07, Korea in 02, and now China vs. CNN in 08). I keep thinking about it in terms of asymmetric warfare, a class of warfare where one side is a traditional, centrally managed military with superior uniformed numbers, weaponry, and skill. On the other we have smaller numbers, usually untrained fighters with meager weapons, and usually a smaller force. Historical examples include the North Vietnamese in the 20th century and even the American Revolution in the 18th century. Clearly this can be an effective strategy for a band of irregulars.

My reading this morning lead me to this article, Asymmetric Warfare: A Primer, by C. A. “Bert” Fowler, in the IEEE Spectrum. In it, Fowler explores a mathematical basis for how one side can drain the resources of the other. Towards the end he expresses the six fundamentals of an insurgency as described by T. E. Lawrence, or irregular force, in classic warfare. These are reiterated in T.E. Lawrence And the Mind of An Insurgent by James J Schneider. Here they are, with their online — and cybercrime — parallels:

1. A successful guerrilla movement must have an unassailable base.

In this case, the irregulars have such a diffuse base of operations — infected computers, possibly spred globally — that a traditional defender cannot identify or stop them preemptively. We’ve hit this a long time ago with botnets, and now with some DDoS nets we’re there again.

2. The guerrilla must have a technologically sophisticated enemy.

No question about it, most of the targets have substantial bandwidth, server, and infrastructure — and people — resources.

3. The enemy must be sufficiently weak in numbers so as to be unable to occupy the disputed territory in depth with a system of interlocking fortified posts.

This parallel is, I think, best drawn when you think about keeping computers uninfected. Every day, new vulnerabilities come out that can be used to spread malware, and every day new social engineering lures come out that render such vulnerabilities moot (for the purposes of infected client computers with your agent).

4. The guerrilla must have at least the passive support of the populace, if not its full involvement.

Again, computers that are often unknowingly infected with a DDoS agent, or in some cases you have a general population that is all too willing to install an agent on their system that will assist in “the cause”.

5. The irregular force must have the fundamental qualities of speed, endurance, presence, and logistical independence.

No doubt about it, the Internet means that speed is now no problem for malware authors and attackers, endurance is easier to find (automation), and with so many groups operating independently, they’re all attacking — and coming together — at will.

6. The irregular must be sufficiently advanced in weaponry to strike at the enemy’s logistics and signals vulnerabilities.

Again, the Internet has leveled the playing field. The same network that the big, powerful force uses to coordinate their system is vulnerable to attacks and shut down, and it’s accessible by the irregular forces.

In short, I don’t think we’ll see an end to this problem any time soon, not without a fundamental, killer blow to the Internet. Any system that can help the “little guy” achieve business greatness against established companies — like Google vs. Microsoft — can also help other, angry “little guys” strike against a giant and sometimes win.

I don’t know if this is the right metaphor, however. In many ways this feels like the lawless streets of Victorian England created in the story of Charles Dickens’ Oliver Twist. If that’s the case then it’s a whole different solution altogether. In the end it may be a mix of the two.

This article originally appeared on Arbor’s Netoworks Security Blog.

Source Credit: This has been a featured post from Jose Nazario, Senior Security Researcher. To learn more, visit this participant's full profile page.

More Under: Cyberattack, Security

Stay Updated: To receive weekly email updates from CircleID sign up here or see the list of RSS feeds and mobile version of this site.

Comments

#1 | By Christopher Parente | Apr 23, 08 @11:53 am PST

Interesting analogy. You seem to wander a bit between military and commercial, however.

When you’re talking about the US military, it’s not the “same network that the big, powerful force uses to coordinate their system is vulnerable to attacks and shut down, and it’s accessible by the irregular forces.“

I assume (and hope!) that it’s a lot harder to mess with SIPRnet than the regular Internet.

Login or Sign Up to add your comments here, get access to CircleID Directory, browse the most popular posts, and more.

Start Your AdAds

Sponsored LinksMarketplace

Industry Updates

May 15, 2008 11:28 AM PST

Overstock.com Chooses NeuStar’s UltraDNS for Managed DNS Service

NeuStar, Inc. has announced that Overstock.com, a popular online closeout retailer, has chosen NeuStar's UltraDNS Managed DNS Service to provide Overstock.com with a global DNS infrastructure that significantly enhances end-user experience and operational security -- and protects revenue in the highly competitive online retail market. ›››

By NeuStar | Views: 134

May 14, 2008 11:37 AM PST

Inside Your Domain Portfolio

We've seen a lot of changes in the domain industry over the last year, some positive, some challenging. Whether you're an old pro or just beginning, this spring is a great time to take inventory and make sure your domain business is on the right track for success this year and beyond. ›››

By Sedo | Views: 160

May 14, 2008 11:32 AM PST

Sedo at Domain Roundtable 2008, San Francisco

Domain Roundtable 2008 was an all-around successful event for Sedo. The conference was attended by the domain industry's best and brightest and the Sedo team was right there in the thick of it. ›››

By Sedo | Views: 158

May 14, 2008 11:27 AM PST

Sedo’s New Brokerage Application

Have you ever wanted to buy or sell a domain or a portfolio of domains but just didn't have the time to market it, manage and negotiate the best possible price? You can now request this premium service and work with an experienced Sedo domain broker. ›››

By Sedo | Views: 203

May 13, 2008 3:00 PM PST

ICANN Unanimously Approves RegistryPro Proposal to Expand the .Pro TLD

RegistryPro, the exclusive operator of the .Pro top level domain (TLD), has received approval from ICANN to greatly expand the scope and availability of the .Pro TLD. The newly ratified terms of service increases the number of professionals who are eligible for the TLD, extends the availability globally, and streamlines the registration process. ›››

By Hostway | Views: 315

May 06, 2008 10:16 AM PST

Oversee.net’s DomainSponsor Presents 3rd Annual DOMAINfest Global

The third annual DOMAINfest Global, the premier conference and networking event for the domain name industry, will be held at the Renaissance Hollywood Hotel in Hollywood, California from January 28-30, 2009. Event registration will open later this year. ›››

By DomainSponsor | Views: 524

May 02, 2008 10:21 AM PST

.NL Auction Sneak Peak!

Join Sedo for our much anticipated .NL auction, being held from May 2nd 4pm (EST) until May 9th at approximately 4pm (EST). As the worth of the .NL continues to increase, so does the demand. ›››

By Sedo | Views: 596

Apr 30, 2008 10:01 AM PST

dotMobi Requests Proposals for find.mobi

dotMobi today announced that is accepting proposals for find.mobi, a consumer-facing mobile search tool; find.mobi was created by dotMobi's research and development team to demonstrate an operational mobile search engine that made the most of the mobile web and needs of on-the-go users. ›››

By dotMobi | Views: 809

Apr 28, 2008 2:08 PM PST

dotMobi Offers Prime Selection of Generic Domain Names to Spur Mobile Web Growth

As part of its ongoing series of unique methods of allocating Internet domain names, dotMobi is bringing 16 "premium names" to market at Moniker's T.R.A.F.F.I.C. East Auction on May 23, 2008. ›››

By dotMobi | Views: 1043

Apr 28, 2008 11:41 AM PST

Sedo’s Better-than-Ever Brokerage Service!

Sedo's brokerage services are being updated with a new process for submitting both buyer and seller side brokerage requests and enhanced communications tools.  ›››

By Sedo | Views: 885

Start Your AdAds