148
Hal Roberts, Ethan Zuckerman, and John Palfrey
speculation that some attacks are traceable to governments — for instance, the example
of http://bauxitevietnam.info — it is unclear that this is an assumption with any merit.
DDoS is a technique used by individuals, groups, and, perhaps, states. The accessibility
of easy-to-use tools and the apparent success of single-user attacks on small Web sites,
as well as the technique ’ s visibility in the media, suggest that aggrieved individuals
may look to DDoS as an easy way of making a political point or settling a score. We
note, too, that the widely reported DDoS attacks in the context of the release of U.S.
State Department cables by Wikileaks in the fall of 2010 involved attacks both on
Wikileaks itself and on major banks and others in apparent retaliation. In an ironic
and perhaps inevitable twist, 4chan — an online community that claimed responsibility for many retaliatory attacks — was taken down by a DDoS on December 28, 2010.
As with other Internet control mechanisms, DDoS is an approach used by a variety of
actors to accomplish a variety of ends.
Conclusion: Situating DDoS in the Context of “ Next-Generation Controls ”
and Other Online Contests
In response to the growing usage of next-generation Internet controls, citizens may
be banding together to fend off DDoS and related attacks, at least on a modest scale.
In three of our interviews, we heard of local technical experts acting as hubs of technical expertise for their countries (in Vietnam, China, and Iran, specifi cally). The most
productive and satisfi ed of these local experts was far along in the process of moving
sites in his country to a common infrastructure well supported by a hosting provider
that was well connected to the core of the Internet (in all senses of “ core ” : community,
expertise, and resources). He was able to exert a great deal of control over the structure
of the moved sites, including imposing onerous security and posting restrictions on
the sites ’ administrators. The most concerned and least content of these local experts
was struggling daily with many poorly written sites on broken, incompatible code
bases, often reinstalling a site from scratch following an intrusion and manually fi ghting off the simpler of the constant DDoS attacks. He told us that he had the desire,
but not the resources, to fi x the underlying problems with the supported sites, as well
as gratitude for the help he has received from other individuals, but he was frustrated
by his inability to fend off high-bandwidth traffi c attacks.
The threat of DDoS attacks is inextricable from other security considerations,
including human resources concerns, technical resources, and community connections. Ultimately, what human rights and independent media organizations face, in
Asia and elsewhere around the world, is a combination of a shortage of skilled siteadministration skills, the bandwidth needed to fend off large network attacks, and the
community connections needed to ask core network operators for help to fend off
attacks. The diffi culty of responding effectively to DDoS attacks is a symptom of a
Hal Roberts, Ethan Zuckerman, and John Palfrey
speculation that some attacks are traceable to governments — for instance, the example
of http://bauxitevietnam.info — it is unclear that this is an assumption with any merit.
DDoS is a technique used by individuals, groups, and, perhaps, states. The accessibility
of easy-to-use tools and the apparent success of single-user attacks on small Web sites,
as well as the technique ’ s visibility in the media, suggest that aggrieved individuals
may look to DDoS as an easy way of making a political point or settling a score. We
note, too, that the widely reported DDoS attacks in the context of the release of U.S.
State Department cables by Wikileaks in the fall of 2010 involved attacks both on
Wikileaks itself and on major banks and others in apparent retaliation. In an ironic
and perhaps inevitable twist, 4chan — an online community that claimed responsibility for many retaliatory attacks — was taken down by a DDoS on December 28, 2010.
As with other Internet control mechanisms, DDoS is an approach used by a variety of
actors to accomplish a variety of ends.
Conclusion: Situating DDoS in the Context of “ Next-Generation Controls ”
and Other Online Contests
In response to the growing usage of next-generation Internet controls, citizens may
be banding together to fend off DDoS and related attacks, at least on a modest scale.
In three of our interviews, we heard of local technical experts acting as hubs of technical expertise for their countries (in Vietnam, China, and Iran, specifi cally). The most
productive and satisfi ed of these local experts was far along in the process of moving
sites in his country to a common infrastructure well supported by a hosting provider
that was well connected to the core of the Internet (in all senses of “ core ” : community,
expertise, and resources). He was able to exert a great deal of control over the structure
of the moved sites, including imposing onerous security and posting restrictions on
the sites ’ administrators. The most concerned and least content of these local experts
was struggling daily with many poorly written sites on broken, incompatible code
bases, often reinstalling a site from scratch following an intrusion and manually fi ghting off the simpler of the constant DDoS attacks. He told us that he had the desire,
but not the resources, to fi x the underlying problems with the supported sites, as well
as gratitude for the help he has received from other individuals, but he was frustrated
by his inability to fend off high-bandwidth traffi c attacks.
The threat of DDoS attacks is inextricable from other security considerations,
including human resources concerns, technical resources, and community connections. Ultimately, what human rights and independent media organizations face, in
Asia and elsewhere around the world, is a combination of a shortage of skilled siteadministration skills, the bandwidth needed to fend off large network attacks, and the
community connections needed to ask core network operators for help to fend off
attacks. The diffi culty of responding effectively to DDoS attacks is a symptom of a
