168
Nart Villeneuve and Masashi Crete-Nishihata
information about Burma to a global audience. This observation helps to explain why
opposition media sites are routinely attacked despite the fact that they are inaccessible
to Internet users within Burma.
Assessing Threat and Attribution
To assess the capabilities of computer network attackers, John Arquilla has defi ned
three useful categories that indicate the skill and resources required to carry out various
levels of attacks:
Simple-Unstructured The capability to conduct basic hacks against individual systems
using tools created by someone else. The organization possesses little target analysis,
command and control, or learning capability.
Advanced-Structured The capability to conduct more sophisticated attacks against
multiple systems or networks and possibly to modify or create basic hacking tools.
The organization possesses an elementary target analysis, command and control, and
learning capability.
Complex-Coordinated The capability for coordinated attacks capable of causing massdisruption against integrated, heterogeneous defenses (including cryptography).
Ability to create sophisticated hacking tools. Highly capable target analysis, command
and control, and organizational learning capability.
57
Analyzing the attacks within this framework grounds political context in technical
data in a way that provides a clearer picture of the identity and intent of the
attackers.
Our analysis suggests that the attackers have signifi cant knowledge of information
technology, which enables them to launch attacks by leveraging basic, publicly available exploits and software tools. They may also have access to botnets capable of DDoS
attacks, but they do not create or own the botnets themselves. In the attack against
Mizzima News, the attackers employed basic means to mask their identities, but did
not or were unable to escalate their user privileges to “ root ” administrator level on
the server or successfully cover their digital tracks. They maintained a low level of
operational security and left behind signifi cant pieces of evidence. The evidence implicates members of the oGc in the attacks, and in particular the oGc ’ s administrator.
The relatively low sophistication of the attack and the capabilities of the attackers
indicate that they are best placed within the “ Simple-Unstructured ” category of Arquilla ’ s framework. However, the fortuitous timing of the attack provided the attackers
with a “ strategic utility ” that would normally be beyond their means.
Despite the correlative evidence, there are several alternative explanations concerning attribution that we have to explore. The administrator of the oGc often suggested
in our IRC chats that Lynn Htun was responsible for the attacks. Lynn Htun has a
Précédent

- 185/431

Suivant