attacks, a ‘‘hacker for hire’’ posted threats to the affected ISPs’ visitor logs, stating that
unless these sites stayed off-line the attacks would continue. 23 The DDoS attacks effectively disrupted the ISPs’ services because the hacker exploited the ISPs’ narrow bandwidths and dependence on a single satellite-based connection. It remains unclear who
hired the hackers responsible for the attack, although an investigation by ONI found
that they were based in Ukraine (and were also responsible for an attack on a U.S. site
using the same ‘‘bot’’ network). The opposition accused the government of ordering
the attacks as a means of undermining them. The government responded by ordering the affected ISPs to keep their resources online, but it was impossible to do so because the DDoS attack had degraded their ability to provide any services. In the end,
the attack was stopped as a result of U.S. legal action against the originating ‘‘botnet,’’
which had also been attacking a U.S. site. When the ‘‘botnet’’ was taken down, the
attacks against the Kyrgyz sites also stopped.
The Case of Belarus (2006) During the March 2006 presidential elections in Belarus,
several opposition Web sites became suddenly inaccessible, ostensibly because of innocuous network faults and domain name system (DNS) failures. Likewise, at the peak of
protests against the election results, a major Minsk-based ISP ceased to provide dial-up
services owing to ‘‘technical problems.’’ These occurrences meant that important independent media and opposition political Web sites were not accessible at periods when
the information they were conveying could have had political significance or acted as a
catalyst for further political action. Although nothing transpired that could be identified as extralegal filtering, de facto access was not available when and where needed,
with some evidence suggesting that tampering may have occured. 24
This form of ‘‘event-based’’ information control, which temporally shapes Internet
access, can be said to represent the emerging next-generation Internet controls. Not
unlike the shorter supply-line chains that boosted manufacturing efficiencies under
‘‘just-in-time’’ production, event-based filtering can also be considered to be ‘‘just-intime,’’ as it offers greater efficiencies in denying access to information when and where
it is needed. At the same time, the fact that this form of targeted and time-limited filtering is much harder to prove also removes the potential liabilities of being caught
undertaking more deliberative filtering.
Crowd-Sourced Attacks: Pro-Government or Patriotic Hacktivists
During the August 2008 Russia-Georgia war over the breakaway territory of Ossetia,
pro-government Russian hackers launched DDoS attacks against a wide range of Georgian ISPs and Web sites. As a consequence, the majority of Georgian government
Web sites, as well as official media sites were inaccessible throughout the conflict. In
response, Georgian ISPs filtered Russian Internet sites to prevent the dissemination of
what they considered inaccurate and inflammatory reports by Russian media. 25 The
effect of the Russian DDoS attacks and Georgian filtering was to create an information
CIS Overview
129
unless these sites stayed off-line the attacks would continue. 23 The DDoS attacks effectively disrupted the ISPs’ services because the hacker exploited the ISPs’ narrow bandwidths and dependence on a single satellite-based connection. It remains unclear who
hired the hackers responsible for the attack, although an investigation by ONI found
that they were based in Ukraine (and were also responsible for an attack on a U.S. site
using the same ‘‘bot’’ network). The opposition accused the government of ordering
the attacks as a means of undermining them. The government responded by ordering the affected ISPs to keep their resources online, but it was impossible to do so because the DDoS attack had degraded their ability to provide any services. In the end,
the attack was stopped as a result of U.S. legal action against the originating ‘‘botnet,’’
which had also been attacking a U.S. site. When the ‘‘botnet’’ was taken down, the
attacks against the Kyrgyz sites also stopped.
The Case of Belarus (2006) During the March 2006 presidential elections in Belarus,
several opposition Web sites became suddenly inaccessible, ostensibly because of innocuous network faults and domain name system (DNS) failures. Likewise, at the peak of
protests against the election results, a major Minsk-based ISP ceased to provide dial-up
services owing to ‘‘technical problems.’’ These occurrences meant that important independent media and opposition political Web sites were not accessible at periods when
the information they were conveying could have had political significance or acted as a
catalyst for further political action. Although nothing transpired that could be identified as extralegal filtering, de facto access was not available when and where needed,
with some evidence suggesting that tampering may have occured. 24
This form of ‘‘event-based’’ information control, which temporally shapes Internet
access, can be said to represent the emerging next-generation Internet controls. Not
unlike the shorter supply-line chains that boosted manufacturing efficiencies under
‘‘just-in-time’’ production, event-based filtering can also be considered to be ‘‘just-intime,’’ as it offers greater efficiencies in denying access to information when and where
it is needed. At the same time, the fact that this form of targeted and time-limited filtering is much harder to prove also removes the potential liabilities of being caught
undertaking more deliberative filtering.
Crowd-Sourced Attacks: Pro-Government or Patriotic Hacktivists
During the August 2008 Russia-Georgia war over the breakaway territory of Ossetia,
pro-government Russian hackers launched DDoS attacks against a wide range of Georgian ISPs and Web sites. As a consequence, the majority of Georgian government
Web sites, as well as official media sites were inaccessible throughout the conflict. In
response, Georgian ISPs filtered Russian Internet sites to prevent the dissemination of
what they considered inaccurate and inflammatory reports by Russian media. 25 The
effect of the Russian DDoS attacks and Georgian filtering was to create an information
CIS Overview
129
