12.07.2015 Views

Introduction to Cyber-Warfare - Proiect SEMPER FIDELIS

Introduction to Cyber-Warfare - Proiect SEMPER FIDELIS

Introduction to Cyber-Warfare - Proiect SEMPER FIDELIS

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SILENCING NOVAYA GAZETA AND OTHER RUSSIAN DISSIDENTS51Center chief, Alexander Andreyechkin stated “Uncontrolled usage of [services like Skype,GMail, or Hotmail] may lead <strong>to</strong> a massive threat <strong>to</strong> Russia’s security.” 52Despite the theories of Kremlin involvement, Russian President Dmitry Medvedev’sLiveJournal page was also taken offline during the attack. 53 We note that by analyzing thenetwork traffic <strong>to</strong> the compromised computers launching a botnet attack, security researcherscan identify which sites were targeted by a specific botnet during a major cyber offensive aswell as how many command and control servers were involved. Based on this knowledge, thebotnet launching the attacks against LiveJournal and Novaya Gazeta at this time was receivingcommands <strong>to</strong> target one or two specific URL’s over a period of a few days. 54 On April 6, therewas a surge in the attacks, with the botnet receiving 36 such URLs—which included http://livejournal.com and http://livejournal.ru. 55 These attacks effectively <strong>to</strong>ok out all LiveJournalusers—including the Russian President. Medvedev made statements condemning the attackson April 7—after his personal blog was attacked. If the Kremlin was involved in the attacks,the 1-day DDoS against Medvedev’s blog site might have been the small price paid <strong>to</strong> maintainplausible deniability for silencing the opposition at a perceived critical juncture.“RUNET” is, at the time of writing, surprisingly free of censorship compared <strong>to</strong> more traditionalmedia like newspapers, television and radio, which are harshly censored. The collateraldamage experienced by the loss of Medvedev’s blog would not inhibit the Russian leadershipfrom communicating their message as they could always resort <strong>to</strong> traditional media—unlikethe opposition. Further, the blocking of Medvedev’s blog leads <strong>to</strong> a counterpropagandacampaign. For instance, on April 7, Reuters ran a s<strong>to</strong>ry entitled “Medvedev criticizes ‘illegal’attack on his blog.” 56Days after the attack, the Novaya Gazeta made a formal request <strong>to</strong> the Russian government<strong>to</strong> investigate the April 2011 DDoS attack against its Web site. 57 It is unknown if any officialaction has been taken with regard <strong>to</strong> this request. In an apparent move <strong>to</strong> appease the public,in February 2011, Russian President Dmitry Medvedev issued an order <strong>to</strong> the head of theFSB, Aleksandr Bortnikov, <strong>to</strong> investigate the November 2010 DDoS against Novaya Gazeta.However, at the time of this writing, no investigation was carried out. 58The Optima/Darkness BotnetOne botnet known <strong>to</strong> be involved in the April 2011 DDoS attack was known as the “DestinationDarkness Outlaw System” 59 also referred <strong>to</strong> as “Optima” or simply “Darkness.” 60The crea<strong>to</strong>rs of this botnet first started renting the use of the botnet—allowing users in thecriminal underworld <strong>to</strong> launch attacks or steal data—in March 2009. 61 However, even thoughthe services of the botnet were advertised for rent at this early stage, the earliest evidence of itsuse was not discovered by security experts until 2010. 62,63 The willingness of botnet authors <strong>to</strong>sell its services is not uncommon. It was observed that, during the time of the LiveJournalattack (March 23-April 1, 2011), besides the various Navalny Web sites (rospil.info andnavalny.livejournal.com), the Web site of the Northwest arm of the Federal office handlingindustrial supervision as well as the Web site of a furniture fac<strong>to</strong>ry, kredo-m.ru, were alsotargeted. 64 The target of a furniture business might indicate a business-<strong>to</strong>-business attackoccurring at the same time as the politically motivated one. 65 Optima/Darkness was welldeveloped by the time of the attack. At that point, the newest version was at least 8—which

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!