Showing posts with label Russia. Show all posts
Showing posts with label Russia. Show all posts

Sunday, June 7, 2009

Kremlin Launches ‘School of Bloggers’ (Danger Room)

Kremlin Launches ‘School of Bloggers’

  • By Nathan Hodge  
  • May 27, 2009  |  
  • 10:34 am

chadayev1Russian President Dmitry Medvedev recently made a foray into Web 2.0 with the launch of his own blog. Now it looks as if the Kremlin’s embrace of social media is tightening.

Evgeny Morozov, who writes Foreign Policy’s fascinating Net.effect blog,stumbled upon the announcement for a series of public lectures on the “Kremlin’s School of Bloggers.” The announcement is on Liberty.ru, a sort of DailyKos for the pro-Kremlin set.

Unfortunately, we missed the inaugural lecture, delivered on May 14 by Alexey Chadayev, the director of the Kremlin’s school of bloggers. Chadayev (pictured, with pipe) already has an impressive resume: He lists his credentials as “famous political scientist, blogger, activist, doctoral candidate in cultural studies, docent at Russian State University of the Humanities, member of the Public Chamber, editor in chief of the online portal Liberty.ru, and author of the book, Putin: His Ideology.” Give this man a Twitter account, and you’ll have the Karl Rove of the Russian establishment.

The Russian government was slow to pick up on new media — meaning it was always a step behind domestic political opposition as well as more serious opponents. Take the case of Kavkaz Center: a pro-Chechen website launched at the beginning of the Second Chechen War in 1999. In the early days of the conflict, Kavkaz Center was an effective propaganda site; it also pioneered a lot of the information warfare tactics seen on jihadist websites, posting “trophy videos” of roadside bomb attacks and ambushes against Russian soldiers. Russian authorities countered with lame sites like Chechnyafree.ru, but they never quite caught on.

But in recent years, the Kremlin and its online supporters have become much more adept at using the Web as a tool of information war. Kavkaz Center was an early target of denial-of-service attacks; Russian “cyber militias” have been blamed for waging cyberwar on Georgia, Kyrgyzstan and Estonia.

With backing from Medvedev, however, the Kremlin seems to view the Web as more of an instrument of soft power instead of as an offensive weapon. Take, for instance, the case of the man who posted a comment on Medvedev’s blog about shabby conditions at a local children’s hospital. The Kremlin responded swiftly, shaming the local authorities into action. It’s an effective way to reinforce the president’s prestige — and it fits in with a historical pattern (”good czar vs. bad boyars“).

Liberty.ru, for instance, seems to be a more sophisticated way to build a community than the pro-Putin youth groups, which bore a disturbing resemblance to totalitarian youth movements of the 1930s. But it still offers up a Bizzaro World version of reality. The homepage, for instance, currently features a web video entitled “Battle for History: Georgia 1989″), which takes a conspiratorial view of the Soviet crackdown in Georgia 20 years ago, suggesting that the CIA was behind nationalist demonstrations that led to Georgia’s independence. If only.

Saturday, February 7, 2009

Cyberwarfare 101: Case Study of a Textbook Attack

If you are tired of reading about the Estonian cyber attacks, then pls don't bother reading this.  The story below is from a blog, but author claims it was originally run by Stratfor.com earlier this year.



Summary

http://blogs.msdn.com/tzink/archive/2008/12/24/cyberwarfare-101-case-study-of-a-textbook-attack-part-1.aspx

One of the most mature instances of a cyberwarfare attack was an assault on Internet networks in Estonia in late April and early May of 2007. The Russian government was suspected of participating in — if not instigating — the attack, which featured some of the key characteristics of cyberwarfare, including decentralization and anonymity.

During the night of April 26-27, 2007, in downtown Tallinn, Estonia, government workers took down and moved a Soviet-era monument commemorating World War II called the Bronze Soldier, despite the protests of some 500 ethnic Russian Estonians. For the Kremlin — and Russians in general — such a move in a former Soviet republic was blasphemy.

It was also just the kind emotional flash point that could spark a "nationalistic" or "rally-around-the-flag" movement in cyberspace. By 10 p.m. local time on April 26, 2007, digital intruders began probing Estonian Internet networks, looking for weak points and marshaling resources for an all-out assault. Bursts of data were sent to important nodes and servers to determine their maximum capacity — a capacity that the attackers would later exceed with floods of data, crashing servers and clogging connections.

A concerted cyberwarfare attack on Estonia was under way, one that would eventually bring the functioning of government, banks, media and other institutions to a virtual standstill and ultimately involve more than a million computers from some 75 countries (including some of Estonia's NATO allies). Estonia was a uniquely vulnerable target. Extremely wired, despite its recent status as a Soviet republic, Estonian society had grown dependent on the Internet for virtually all the administrative workings of everyday life — communications, financial transactions, news, shopping, restaurant reservations, theater tickets and bill paying. Even parliamentary votes were conducted online. When Estonia's independence from the Soviet Union was restored in 1991, not even telephone connections were reliable or widely available. Today, more than 60 percent of the population owns a cell phone, and Internet usage is already on par with Western European nations. In 2000, Estonia's parliament declared Internet access a basic human right.

Some of the first targets of the attack were the Estonian parliament's e-mail servers and networks. A flood of junk e-mails, messages and data caused the servers to crash, along with several important Web sites. After disabling this primary line of communications among Estonian politicians, some of the hackers hijacked Web sites of the Reform Party, along with sites belonging to several other political groups. Once they gained control of the sites, hackers posted a fake letter from Estonian Prime Minister Andrus Ansip apologizing for ordering the removal of the World War II monument.

By April 29, 2007, massive data surges were pressing the networks and rapidly approaching the limits of routers and switches across the country. Even though not all individual servers were taken completely offline, the entire Internet system in Estonia became so preoccupied with protecting itself that it could scarcely function.

During the first wave of the assault, network security specialists attempted to erect barriers and firewalls to protect primary targets. As the attacks increased in frequency and force, these barriers began to crumble.

Seeking reinforcements, Hillar Aarelaid, chief security officer for Estonia's Computer Emergency Response Team, began calling on contacts from Finland, Germany, Slovenia and other countries to assemble a team of hackers and computer experts to defend the country. Over the next several days, many government ministry and political party Web sites were attacked, resulting either in misinformation being spread or the sites being made partially or completely inaccessible.

After hitting the government and political infrastructure, hackers took aim at other critical institutions. Several denial-of-service attacks forced two major banks to suspend operations and resulted in the loss of millions of dollars (90 percent of all banking transactions in Estonia occur via the Internet). To amplify the disruption caused by the initial operation, hackers turned toward media outlets and began denying reader and viewer access to roughly half the major news organizations in the country. This not only complicated life for Estonians but also denied information to the rest of the world about the ongoing cyberwar. By now, Aarelaid and his team had gradually managed to block access to many of the hackers' targets and restored a degree of stability within the networks.

Then on May 9, the day Russia celebrates victory over Nazi Germany, the cyberwar on Estonia intensified. Many times the size of the previous days' incursions, the attacks may have involved newly recruited cybermercenaries and their bot armies. More than 50 Web sites and servers may have been disabled at once, with a data stream crippling many other parts of the system. This continued until late in the evening of May 10, perhaps when the rented time on the botnets and cybermercenaries' contracts expired. After May 10, the attacks slowly decreased as Aarelaid managed to take the botnets offline by working with phone companies and Internet service providers to trace back the IP addresses of attacking computers and shut down their Internet service connections.

During the defense of Estonia's Internet system, many of the computers used in the attacks were traced back to computers in Russian government offices. What could not be determined was whether these computers were simply "zombies" hijacked by bots and were not under the control of the Russian government or whether they were actively being used by government personnel.

Although Estonia was uniquely vulnerable to a cyberwarfare attack, the campaign in April and May of 2007 should be understood more as a sign of things to come in the broader developed world. The lessons learned were significant and universal. Any country that relies on the Internet to support many critical, as well as mundane day-to-day, functions can be severely disrupted by a well-orchestrated attack. Estonia, for one, is unlikely ever to reduce its reliance on the Internet, but it will undoubtedly try to develop safeguards to better protect itself (such as filters that restrict internal traffic in a crisis and deny anyone in another country access to domestic servers). Meanwhile, the hacker community will work diligently to figure out a way around the safeguards.

One thing is certain: Cyberattacks like the 2007 assault on Estonia will become more common in an increasingly networked world, which will have to learn — no doubt the hard way — how to reduce vulnerability and more effectively respond to such attacks. Perhaps most significant is the reminder Estonia provides that cyberspace definitely favors offensive operations.

Are 'Cyber-Militias' Attacking Kyrgyzstan?

FEBRUARY 5, 2009, 1:01 PM

By ROBERT MACKEY

http://thelede.blogs.nytimes.com/2009/02/05/are-cyber-militias-attacking-kyrgyzstan/?hp

In The Guardian, Danny Bradbury writes that before Kyrgyzstan made news this week by threatening to evict the United States military from a leased airbase, the country apparently endured a two-week attack on its Internet service by what one Web security expert called a "cyber-militia" based in Russia.

Mr. Bradbury reports that from Jan. 18 until last weekend, Kyrgyzstan, a former Soviet republic, was "pummeled by a massive distributed denial of service attack." In The Wall Street Journal last week, Christopher Rhoads reported that Don Jackson, the director of threat intelligence at an Atlanta-based Internet security firm called SecureWorks, pointed the finger at "Russia's cyber underground." As Mr. Rhoads wrote in The Journal:

The denial-of-service attack — which swamps Web sites with so many hits that they are forced to shut down — has targeted the two main Internet service providers in the country, which account for more than 80 percent of Kyrgyzstan's bandwidth, according to Mr. Jackson. The episode has shut down Web sites and made e-mailing impossible, he said.

On Mr. Jackson's SecureWorks blog, he summed up his findings last week:

The two primary Kyrgyzstan ISPs (www.domain.kg, www.ns.kg) have been under a massive, sustained DDoS attack almost identical in some respects to those that targeted Georgia in August 2008. Few alternatives for Internet access exist in Kyrgyzstan. With just two smaller IPSs left to handle the load, these attacks from Russian IP address space1,2 have essentially knocked most of the small Central Asian republic offline.

Last August, it was widely reported that, as CNET reported, the Georgian government had "accused forces within Russia of launching a coordinated cyberattack against Georgian Web sites, to coincide with military operations in the breakaway region of South Ossetia." On his blog, Mr. Jackson quotes Alexander Denezhkin, from the Russian firm Cybersecurity.ru, who said at the time, "Cyber-attacks are part of the information war, making your enemy shut up is a potent weapon of modern warfare."

(For more background on the August attacks on Georgian ether, see The Times' Mike Nizza's reporting for The Lede, and John Markoff's poston our sibling blog (blogling?) Bits.)

But Mr. Bradbury reports that another Web security expert, Jeffrey Carr, does not share Mr. Jackson's belief that the Russian government is responsible for the attacks. In a post on Mr. Carr's blog — headlined "Why I believe that the Kyrgyzstan Government hired Russian hackers to launch a DDOS attack against itself" — he explains that he thinks this is part of a government crackdown on an opposition party in Kyrgyzstan that uses the Internet to organize. Mr. Carr writes:

The most direct way to discover the motive behind the attacks is to look at what's happening simultaneously WITH the attacks. I created a list here. All but one are related to the formation of the United Popular Movement (UPM), who are calling for the ouster of Bakiyev because of cronyism and his lack of democratic reforms, as well as his inability to fix the ailing economy of the country. Denying the UPM Internet access, along with arresting their leaders, is a classic one-two punch.

Almost this exact scenario happened in 2005 when Bakiyev, then an opposition leader, successfully led a regime change against then President Akayev. Cyber attacks occured then as well, effectively blocking access to opposition Web sites.

Finally, the Kyrgyz government has the ability to combat this threat, and the office responsible has done nothing about it.

"This is not a sophisticated attack, and its being routed through Russian servers," Mr. Carr continued, adding that if the Kyrgyz government wanted to stop the attack, "it would be a relatively easy matter for them to do so."

If the government is indeed using cyber-militias to suppress political opposition, that would be a sad end to the story of the country's president, Kurmanbek Bakiyev, who led the "so-called Tulip Revolution" that forced the previous president out of office in 2005, and who was then elected president himself with nearly 90 percent of the vote. (Doubts about that revolution's true nature were raised within days, though: Craig Smith reported from Kyrgyzstan for The New York Times in 2005 that "the uprising a week ago begins to look less like a democratically inspired revolution and more like a garden-variety coup.")

Whatever the motive behind the attacks, a blogger at HostExploit.com sees describes the attacks on Kyrgyzstan as the drawing of a "Cyber Iron-Curtain" across the Internet as it runs through Russia to other countries that were once part of the Soviet Union.

Sunday, August 10, 2008

Georgian Web Sites Under Attack

http://voices.washingtonpost.com/securityfix/2008/08/georgian_web_sites_under_attac.html?nav=rss_blog
by: Brian Krebs

As Russian bombs rained down on towns in separatist towns of the former Soviet republic of Georgia, hackers mounted a digital assault on the nation's top Web properties this week, knocking government Web sites offline and defacing others.

According to reports from security experts who have been monitoring the ongoing cyber attacks, the Web site for the office of Georgia Foreign Affairs (mfa.gov.ge) was hacked, and its homepage was replaced with images depicting Georgia's president as a Nazi. That site is currently offline.

Other Georgian Web properties, such as the Caucasus Network Tbilisi -- key Georgian commercial Internet servers -- remain under sustained attack from thousands of compromised PCs aimed at flooding the sites with so much junk Web traffic that they can no longer accommodate legitimate visitors.

Security Blogger Jart Armin has been tracking the attacks by conducting Internet traces and lookups at key Georgian Web properties.

The apparently coordinated cyber attacks are reminiscent of recent cyber wars waged against other former Soviet republics that have attracted the ire of the Russian government for various political reasons. Last month, a similar assault targeted important Lithuanian government Web sites. In April 2007, the ultra-wired country suffered major disruptions in much of its information infrastructure, thanks largely to Russian hackers who were upset over the removal of a Soviet World War II memorial from the center of Tallinn, the capital of Estonia.