Interconnected Contests
147
(meaning that all or many of those are likely to be attacked at critical times for the
country). As we noted previously, sometimes an attack will outstrip an administrator ’ s
ability to pay the associated bandwidth charges, and the site will be forced to go dark
until the attack ceases.
Given the trade-offs of the various defense mechanisms, it is critical for sites that
know they are likely to be attacked to weigh the various options before they are
affected by DDoS. For instance, site administrators will need to know whether to pay
the startup costs to hire a protection service, how much to pay a service to withstand
a traffi c-based attack, and at what point to accept that the cost of defending against
a given attack is too high.
Hiding Their Tracks? Ample Suspicion, but No Hard Evidence, That States Are
Involved in DDoS
Most sites participating in the interviews expressed a strong belief that the national
government of the country their site reported on was ultimately responsible for the
attacks. None, however, had clear evidence of state responsibility. One participant had
reported a large, ongoing attack to the state ’ s security service but got no help since “ it
is very diffi cult to look into this because it is very diffi cult to catch yourself. ” He
asserted that the security service shut down its own attack only when other publications better connected to the government complained. One Vietnamese site pointed
to a press report of a Vietnamese military offi cial claiming responsibility for the
attacks.
14 As mentioned previously, a Viet Tan administrator noted that his site was
normally fi ltered from within Vietnam but that the fi ltering was taken down at precisely the time that a botnet from within Vietnam attacked the site. Most interview
participants asserted the opinion that the national government was responsible for
the attacks but did not claim any direct evidence for the responsibility. This inability
to attribute direct responsibility for DDoS attacks is typical for the attacks. The distributed nature of the attacks makes it diffi cult to assign responsibility — it is certainly
possible that either a government or progovernment individuals could attack a site
critical of a specifi c regime, and our inability to trace the attack would not be an
unusual circumstance. Our fi ndings in these respects are consistent with the fi ndings
of Villeneuve and Crete-Nishihata in chapter 8.
As a related matter, we also found no obvious connection between the particular
ideology of an attacker and the choice of DDoS as an attack method. We saw attacks
from ostensibly right- and left-wing groups, attacks that targeted governments, and
attacks that suggest government involvement. Neither is there an apparent geographic
pattern to the DDoS attacks we saw in our media analysis. We found attacks reported
in widely disparate corners of the world. Asian states were a common site for DDoS
attacks, but certainly not the only region where they appear. While there is
147
(meaning that all or many of those are likely to be attacked at critical times for the
country). As we noted previously, sometimes an attack will outstrip an administrator ’ s
ability to pay the associated bandwidth charges, and the site will be forced to go dark
until the attack ceases.
Given the trade-offs of the various defense mechanisms, it is critical for sites that
know they are likely to be attacked to weigh the various options before they are
affected by DDoS. For instance, site administrators will need to know whether to pay
the startup costs to hire a protection service, how much to pay a service to withstand
a traffi c-based attack, and at what point to accept that the cost of defending against
a given attack is too high.
Hiding Their Tracks? Ample Suspicion, but No Hard Evidence, That States Are
Involved in DDoS
Most sites participating in the interviews expressed a strong belief that the national
government of the country their site reported on was ultimately responsible for the
attacks. None, however, had clear evidence of state responsibility. One participant had
reported a large, ongoing attack to the state ’ s security service but got no help since “ it
is very diffi cult to look into this because it is very diffi cult to catch yourself. ” He
asserted that the security service shut down its own attack only when other publications better connected to the government complained. One Vietnamese site pointed
to a press report of a Vietnamese military offi cial claiming responsibility for the
attacks.
14 As mentioned previously, a Viet Tan administrator noted that his site was
normally fi ltered from within Vietnam but that the fi ltering was taken down at precisely the time that a botnet from within Vietnam attacked the site. Most interview
participants asserted the opinion that the national government was responsible for
the attacks but did not claim any direct evidence for the responsibility. This inability
to attribute direct responsibility for DDoS attacks is typical for the attacks. The distributed nature of the attacks makes it diffi cult to assign responsibility — it is certainly
possible that either a government or progovernment individuals could attack a site
critical of a specifi c regime, and our inability to trace the attack would not be an
unusual circumstance. Our fi ndings in these respects are consistent with the fi ndings
of Villeneuve and Crete-Nishihata in chapter 8.
As a related matter, we also found no obvious connection between the particular
ideology of an attacker and the choice of DDoS as an attack method. We saw attacks
from ostensibly right- and left-wing groups, attacks that targeted governments, and
attacks that suggest government involvement. Neither is there an apparent geographic
pattern to the DDoS attacks we saw in our media analysis. We found attacks reported
in widely disparate corners of the world. Asian states were a common site for DDoS
attacks, but certainly not the only region where they appear. While there is
