Cyber attack on Georgia came weeks before invasion

NY Times:

Weeks before physical bombs started falling on Georgia, a security researcher in suburban Massachusetts was watching an attack against the country in cyberspace.

Jose Nazario of Arbor Networks in Lexington noticed a stream of data directed at Georgian government sites containing the message: win+love+in+Rusia.

Other Internet experts in the United States said the attacks against Georgia’s Internet infrastructure began as early as July 20, with coordinated barrages of millions of requests — known as distributed denial of service, or D.D.O.S., attacks — that overloaded certain Georgian servers.

The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved.

Researchers at Shadowserver, a volunteer group that tracks malicious network activity, reported that the Web site of the Georgian president, Mikheil Saakashvili, had been rendered inoperable for 24 hours by multiple D.D.O.S. attacks. The researchers said the command and control server that directed the attack, which was based in the United States, had come online several weeks before it began the assault.

As it turns out, the July attack may have been a dress rehearsal for an all-out cyberwar once the shooting started between Georgia and Russia.

According to Internet technical experts, it was the first time a cyberattack had coincided with a shooting war. But it will likely not be the last, said Bill Woodcock, the research director of the Packet Clearing House, a nonprofit that tracks Internet traffic. He said cyberattacks are so inexpensive and easy to mount, with few fingerprints, that they will almost certainly remain a feature of modern warfare.

“It costs about 4 cents per machine,” Mr. Woodsock said. “You could fund an entire cyberwarfare campaign for the cost of replacing a tank tread, so you would be foolish not to.”

Shadowserver saw the attack against Georgia spread to computers throughout the government after Russian troops invaded the Georgian province of South Ossetia on Sunday.

Georgina media, communications and transportation companies were also targeted, according to security researchers.

...

A Russian government spokesman said that the government was not involved, but that it was possible that individuals in Russia or elsewhere had taken it upon themselves to start the attacks.

...

The attacks were controlled from a server based at a telecommunications firm in Moscow, he said. In contrast, the attacks last month came from a control computer that was based in the United States. That system was later disabled.

...


This suggest to me that the claimed provocation for the Russian attacks was just a pretext for a long planned operation against Georgia. Putin and the Russian governments bazaar statements about the provocation never made any sense, and they offered little evidence to support them. They were also inconsistent with their own conduct in Chechnya.

Comments

Popular posts from this blog

Should Republicans go ahead and add Supreme Court Justices to head off Democrats

Is the F-35 obsolete?

Apple's huge investment in US including Texas facility