Interconnected Contests
141
exactly 500 IP addresses. The attack was highly effective, rendering the site inaccessible
for 12 hours, despite steady work from the Berkman Center ’ s highly experienced
technical staff to keep the site online. That the attack came from a round number of
attacking IPs and that the IP addresses in use shifted in real time in response to
defenses suggests that the application attack came through a rented botnet.
We also saw a strong correlation between DDoS, fi ltering, defacement, and intrusion
attacks in our media analysis. These techniques were often used in conjunction, and
may have synergistic effects — making a site more DDoS resistant can make it more
diffi cult to access using a Web proxy, for instance, which makes state-based fi ltering
more effective. Independent media organizations participating in the working meeting
repeated the same theme: sites suffer from multiple types of attacks, including DDoS,
which in turn have complicated impacts on one another.
A key example of these impacts was the problems that a prominent Burmese
independent Web site experienced from a combination of DDoS attacks and national
fi ltering. The Web site has moved to a DDoS-resistant hosting provider to protect
itself against high-bandwidth-traffi c attacks. The site in question is routinely fi ltered
by the Burmese government, so people within the country must use proxies to access
the site. Burmese users gravitate toward a small set of proxies discovered through
word of mouth. All the traffi c from each of those proxies appears to come from the
same IP address. One method the DDoS-resistant hosting provider uses to protect
against attacks is to block IP addresses that are submitting too many requests. Since
the proxies submit many more requests than other IP addresses, the hosting provider
often bans them, to the end effect of blocking Burmese audiences from accessing
the site. It is possible to address this problem by providing the hosting provider with
a white-list of proxy servers, but that list is diffi cult to maintain because users in
Burma keep seeking new proxies to stay one step ahead of government efforts to
block them.
Non-DDoS attacks on a site are often more serious and less tractable than DDoS
attacks. A common method for intrusions is to compromise the computer of someone
who has administrator-level access to the target server. Access to the server is then
used to delete sites; to discover the identities of dissidents, authors, and sources for
further on- and offl ine harassment; to deface the target site; or to implant malware
on the target site either to discredit the target site or to execute a DDoS attack on
another site or both. Administrators of human-rights-related independent media consistently report being frequently subject to specifi cally targeted e-mail viruses, often
connected to content tailored to be of interest to the administrator in question.
These specifi cally targeted attacks are very diffi cult to defend against, requiring a
high level of training and support for the victims. But many or most of the independent media organizations struggle to maintain even very simple client-side technology infrastructures.
141
exactly 500 IP addresses. The attack was highly effective, rendering the site inaccessible
for 12 hours, despite steady work from the Berkman Center ’ s highly experienced
technical staff to keep the site online. That the attack came from a round number of
attacking IPs and that the IP addresses in use shifted in real time in response to
defenses suggests that the application attack came through a rented botnet.
We also saw a strong correlation between DDoS, fi ltering, defacement, and intrusion
attacks in our media analysis. These techniques were often used in conjunction, and
may have synergistic effects — making a site more DDoS resistant can make it more
diffi cult to access using a Web proxy, for instance, which makes state-based fi ltering
more effective. Independent media organizations participating in the working meeting
repeated the same theme: sites suffer from multiple types of attacks, including DDoS,
which in turn have complicated impacts on one another.
A key example of these impacts was the problems that a prominent Burmese
independent Web site experienced from a combination of DDoS attacks and national
fi ltering. The Web site has moved to a DDoS-resistant hosting provider to protect
itself against high-bandwidth-traffi c attacks. The site in question is routinely fi ltered
by the Burmese government, so people within the country must use proxies to access
the site. Burmese users gravitate toward a small set of proxies discovered through
word of mouth. All the traffi c from each of those proxies appears to come from the
same IP address. One method the DDoS-resistant hosting provider uses to protect
against attacks is to block IP addresses that are submitting too many requests. Since
the proxies submit many more requests than other IP addresses, the hosting provider
often bans them, to the end effect of blocking Burmese audiences from accessing
the site. It is possible to address this problem by providing the hosting provider with
a white-list of proxy servers, but that list is diffi cult to maintain because users in
Burma keep seeking new proxies to stay one step ahead of government efforts to
block them.
Non-DDoS attacks on a site are often more serious and less tractable than DDoS
attacks. A common method for intrusions is to compromise the computer of someone
who has administrator-level access to the target server. Access to the server is then
used to delete sites; to discover the identities of dissidents, authors, and sources for
further on- and offl ine harassment; to deface the target site; or to implant malware
on the target site either to discredit the target site or to execute a DDoS attack on
another site or both. Administrators of human-rights-related independent media consistently report being frequently subject to specifi cally targeted e-mail viruses, often
connected to content tailored to be of interest to the administrator in question.
These specifi cally targeted attacks are very diffi cult to defend against, requiring a
high level of training and support for the victims. But many or most of the independent media organizations struggle to maintain even very simple client-side technology infrastructures.
