Interconnected Contests
135
possibly logging keystrokes and capturing passwords to online accounts, even possibly
collecting the list of e-mail addresses used to encourage more people to download the
Trojan software.
The administrators of bauxitevietnam.info defended the site from the DDoS attack
by mirroring the site on multiple hosting providers. They created mirrors at http://
bauxitevietnam.info , http://boxitvn.org , http://boxitvn.net , http://boxitvn.info ,
http://boxitvn.blogspot.com , and http://boxitvn.wordpress.com . The last two of
these mirroring environments are especially important, because they are hosted by
large blog-hosting services, Blogger (run by Google) and WordPress. These large-scale
services offer highly DDoS-resistant services at no direct fi nancial cost to the
activists.
It is very rare that an observer can come to identify the owner of any botnet, as
Nart Villeneuve and Masashi Crete-Nishihata also fi nd in their fi ne-grained review of
DDoS and defacement attacks in Burma in chapter 8 of this volume. It is the nature
of a botnet to be distributed across a broad range of computers infected without the
knowledge of their owners. Accordingly, no one (including Google and McAfee, two
of a handful of actors most capable of diagnosing this sort of attack) has managed to
determine who controlled the botnet during the course of the Bauxitevietnam attacks —
or, for that matter, who controls it at the time of this writing. But there are indications
that some DDoS attacks against Vietnamese sites have involved more than tacit
approval of the Vietnamese government. Viet Tan, a Vietnamese prodemocracy dissident group, reports that their site is routinely subject to DDoS attacks and that many
of the attacking computers are based in Vietnam.
7 Since http://viettan.org is generally
blocked in Vietnam, these attacks require that authorities lift the blocks on attacked
sites to permit attacks from zombie computers in Vietnam. It is diffi cult to verify this
claim without access to Viet Tan ’ s server logs documenting such an attack.
This example — by no means extraordinary, particularly in Asia — shows how DDoS
attacks accompany a range of interventions that involve malware and related intrusions into the computers of ordinary Internet users. It demonstrates that governments
and other political actors are using a broad array of intertwined methods to contest
online (and offl ine) content that they fi nd offensive. For example, the methods of
attack in this case include the following:
• DDoS attacks
• Technical Internet fi ltering
• Surveillance
• Intrusion by means of malware
• Trojan software
• Online identity forgery
• Offl ine harassment
Précédent

- 152/431

Suivant