DDoS attacks on Estonia "not from Kremlin"
By Rene Millman,
The DDoS attacks affecting Estonia were the spontaneous product of a loose federation of separate attacks rather than a concerted effort by a single government agency, according to data gathered by an IT security company.
The information collated by Arbor Networks showed that the source of attacks were worldwide rather than just from a few locations. The attackers used a giant network of botnets - perhaps as many as one million computers in places as far away as the US and Vietnam, to increase the impact of the attack.
The attacks came after a statue of a Russian soldier was moved from the centre of the Estonian capital Tallinn to a suburban graveyard, prompting outrage from Russia.
The DDoS attacks at their height streamed 90Mbps of data at Estonian networks for period of up to 10 hours. The company said that this was the equivalent of downloading the whole of Windows XP every six seconds.
"We do know that the sites affected (the Parliament, the Ministries of Finance and Agriculture and others) were offline or unavailable for hours at a time during the attacks," said Jose Nazario, senior security engineer at Arbor Networks.
"This is disruption, but as to how much this affected daily life for the average Estonian, it is not very clear."
He said that there was no evidence that these attacks targeted resources that every citizen would use (such as electricity grids or other control systems). And no sizable attacks against Estonian internet infrastructure were observed.
"Most of the attacks appeared more about making a statement at a high profile website or two than about disrupting Estonia's online life or economy," he said.
Nazario said that the source of the attacks were global in nature and not concentrated in one country.
"We know from tracking botnets that at least one or two botnets were involved in some of the attacks," said Nazario. "However, we've also seen non-botnet tools that turned peoples' computers into packet sources."
He said while there were signs of Russian nationalism at work, there was no government connection.
"None of the sources we have analysed from around the world show a clear line from Moscow to Tallinn; instead, it's from everywhere around the world to Estonia. Spoofed sources are easy to provide, but we see no evidence of who is behind the attacks supposedly coming from Moscow," said Nazario.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
Who to trust after the VeriSign hack?
Davey Winder questions what data was stolen from VeriSign and wonders why the company hasn't been more forthcoming.
- Striving to solve the security skills crisis
- Would you employ a hacker or malware writer?
- Q&A: Raj Samani, CTO McAfee
- Erase and rewind: the EU and privacy
- My email address is [CENSORED]
- Is there such a thing as a secure tablet?
- 2011: The year in news
- BYOD: Old or new, good or bad?
- Are the cookie laws crumbling already?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Google releases Chrome for Android beta
- Will someone rid me of these troublesome Macs?
- OneNote hits Google?s Android
- BlackBerry Bold 9790 review
- Google sends in Bouncer to sort out malicious apps
- Ubuntu vs. Windows 7 on the business desktop
- Who to trust after the VeriSign hack?
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- ACTA: the basics, the controversies, and the future
- BT considering Ofcom price cap appeal
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





