Welcome | Sign In
TechNewsWorld.com
Cyberattacks

Suspicion Centers on N. Korea in DoS Blitz but No Smoking Gun

Print Version
E-Mail Article
Reprints
Suspicion Centers on N. Korea in DoS Blitz but No Smoking Gun

Private Web sites in the U.S., along with government sites in both the U.S. and South Korea, were hit with denial of service attacks last weekend, slowing them down and in some cases taking them offline temporarily. Security experts suspect the government of North Korea to be behind the cyberattacks, but they add it's often difficult to figure out exactly who's behind assaults like these.


Crystal Reports - Discover the Latest Innovations.
Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.

U.S. computer security experts didn't have much of an Independence Day holiday this year, thanks to a massive botnet-driven attack launched on July 4 that initially targeted several federal agency Web sites and then went wider to include assaults on private sector Web entities in America and sites for South Korean government departments.


cyberattack
A Seoul police official gives a briefing about
cyberattacks that paralyzed major South Korean
and U.S. Web sites.

The denial of service (DoS) attacks, which reportedly began Saturday and were still hammering away as of Tuesday, shut down or slowed response times for Web sites of the Treasury and Transportation departments, the Secret Service and the Federal Trade Commission, among others. The inclusion of South Korean targets has some officials in that country blaming North Korea or its sympathizers, but cybersecurity analysts say it's very difficult to lay such DoS attacks at the feet of a particular nation-state.

The Department of Homeland Security's Computer Emergency Response Team (CERT) did not comment on any possible ties to North Korea, but a spokesperson did say that DHS is aware of the attacks and is advising all the affected agencies on how to help mitigate any problems.

"We see attacks on federal networks every day, and measures in place have minimized the impact to federal Web sites," DHS deputy press secretary Amy Kudwa told TechNewsWorld. "US-CERT will continue to work with its federal partners and the private sector to address this activity."

The Nature of the Attack

The offending computer code has been under Joe Stewart's microscope since the Fourth of July weekend.

It's not a particularly sophisticated piece of malware, said Stewart, who's director of malware research at Secure Works. There's nothing unusual in its antivirus evasion techniques, its command-and-control protocol, or the way it sends data packets slamming up against Web sites to slow or shut them down.

What is curious is its trigger mechanism: On July 5, it started with six U.S government Web site targets, then expanded to 21 targets on July 6 (with some of those including commercial Web sites in America). On July 7, it removed some previous Web sites from its crosshairs and replaced them with 26 South Korean government agencies.

"They started out with a fairly small attack, then ramped it up in terms of broadness," Stewart told TechNewsWorld. "If you think about that, that's making each attack less effective because they're now having to share that attack bandwidth. They're more interested in getting attention rather than having real DoS effects on the sites that they're after. They're trying to attack whoever they think it important enough to warrant headlines, is how I see it."

Could North Korea Be the Culprit?

Using a botnet -- a network of thousands of infected "zombie" computers unwittingly used to send out nasty code -- to stage a denial-of-service attack doesn't require that much sophistication. It could well be within the reach of a nation-state like North Korea.

If Kim Jong-Il's regime is behind this attack, "I think it's a real problem, but I also don't think North Korea has done anything beyond what script kiddies do," Gary McGraw, chief technology officer for Cigital, told TechNewsWorld. "Most commercial Web sites are under almost constant denial-of-service attack and have learned to cope with it."

The difficulties in tracing a botnet-launched DoS attack back to its original source make it tough to hang an intelligence indictment on a hostile country.

"That's the problem with the Internet," McGraw said. "In fact, it's an issue with the Department of Defense, which is trying to figure out war doctrine with cyberwarfare. Is a pre-emptive strike allowed? Do you have to put out a 'flag on your tank,' as it were? In these cases, it would be fairly straightforward to frame a nation-state or terrorist organization or whatever. That's the trouble here."

Technology and Motivation

North Korea may be inconsistent with its missile accuracy, but observers shouldn't try to equate the quality of that program with its cyberwarfare capabilities, according to Rodger Baker, director of East Asian analysis for Stratfor.

"It's not a perfect comparison," Baker told TechNewsWorld. "One of the big differences is that the North Koreans just don't have the airspace or capability to really test their missile systems. It takes a lot of failures to be successful, and they haven't done enough testing.

"Actually, given the flight operations they've had, their program has been successful," noted Baker. "With their computer systems, they have more ability to test their attacks. The other thing is, you can often mask where they're coming from. Who knows if the [cyber] attacks blamed on the Chinese really take place in China?"

North Korea has been working over the better part of the past decade on shoring up its computer warfare capabilities, Baker has found through his own research. Unlike cyberattacks blamed on Chinese or Russian state hackers, where there may be collusion with non-government cyber-experts, "in North Korea, it can be assumed that activities coming out of North Korea are much more closely controlled and integrated with the government."

It could indeed have been Kim's government launching the latest attack, since it occurred between July 4 and Wednesday -- the 15th anniversary of Kim il Sung's death.

"That becomes symbolic," said Baker. "Also, North Koreans didn't have another long-range missile ready, and they needed something else to demonstrate their capability for messing around outside of their country."


Print Version E-Mail Article Reprints More by Renay San Miguel


More by Renay San Miguel

Cyber-Meltdown: Managing the Message When IT Hits the Fan
November 06, 2009
The situation is a perfect nightmare for any megacorporation: Firewalls are breached, mountains of sensitive data are stolen, and the smell of extortion is in the air. Luckily for all involved, the cyberattack that experts tackled at the 20th World Congress of the Information Security Forum was merely a simulation. The exercise's take-aways, however, proved revealing.
Droid: Enjoyed
November 06, 2009
The Motorola Droid may well be the most intriguing smartphone to come along since Apple redefined the term in 2007. Comparisons with the iPhone are inevitable, of course -- Droid loses on app shop size but wins with its carrier, Verizon. People who use a great deal of Google applications will find Droid especially useful.
Microsoft Scrapes Years of Mold Off MSN Portal
November 04, 2009
A decade ago -- the last time Microsoft gave its MSN site a facelift -- Google was in its infancy, Facebook's Mark Zuckerberg was in high school, and AOL was an Internet portal king. Microsoft has shown a preview of what MSN.com will look like starting early next year, with new emphasis on social networking, local news, and its Bing search engine.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network