through computer-based information attacks. Although there are several tactics that
can be employed within this rubric—deliberate tampering with domain name servers,
virus and Trojan horse insertion, and even brute physical attacks—the most common
is the use of DDoS attacks. These attacks flood a server with illegitimate requests for information from multiple sources—usually from so-called ‘‘zombie’’ computers that are
infected and employed as part of a ‘‘botnet.’’ The ONI has monitored an increasing
number of just-in-time blocking incidences using DDoS attacks, going back to our first
acquaintance during the Kyrgyzstan parliamentary elections of 2005. In that episode,
the Web sites of opposition newspapers came under a debilitating attack that left
them unable to communicate during the critical period leading up to and during the
Kyrgyz election. 8 Since the Kyrgyz case, DDoS attacks have featured prominently in
the dispute between Russia and Estonia in May 2007, during the Russia-Georgia conflict of 2008, and in numerous cases involving the Web sites of human rights and political opposition groups.
These tactics are particularly difficult to monitor using traditional ONI methods
because of their temporary and fleeting duration, and because their perpetrators can
disguise their involvement through distribution and anonymity. Today, organized
criminal networks operate commercial botnets with significant powers of disruption.
Perpetrators can simply contract out a DDoS attack and benefit by the convenience of
an electronic assault that from the outside may look as though it is a random attack or
a series of unfortunate network errors. Attributing such attacks to their source is difficult because the vectors are distributed and the transactions are done through criminal
activity and illicit shadow markets. Although much of what the ONI has observed in
terms of computer network attacks and just-in-time blocking has occurred in the developing world, it is noteworthy the military use of botnets is being debated in NATO
countries and elsewhere. 9 The prospect of an arms race in cyberspace looms large.
Among many countries in the industrialized world, a major impetus to filter is the
desire to control access to information relating to the sexual exploitation of children,
otherwise known as child pornography. In almost all countries, possession and distribution of child pornography is illegal. In some countries, laws have been enacted to
restrict distribution of child pornography online. In some countries, private ISPs have
entered into voluntary arrangements to filter access to lists of child pornographic material, while in others entire nationwide filtering schemes have been proposed. In all
cases, the proposals have been the subject of considerable public debate and controversy. Although only a few very extreme minority groups, such as libertarians, question the right to access child pornography, many have raised questions about the
transparency of the processes being followed or the mechanisms put in place for oversight and review. For the ONI, for example, the mere test for access to this material is
prohibited because a simple connection to such a site would constitute a crime in most
jurisdictions. This situation leaves many researchers in a quandary as to how to verify
8
Ronald Deibert and Rafal Rohozinski
can be employed within this rubric—deliberate tampering with domain name servers,
virus and Trojan horse insertion, and even brute physical attacks—the most common
is the use of DDoS attacks. These attacks flood a server with illegitimate requests for information from multiple sources—usually from so-called ‘‘zombie’’ computers that are
infected and employed as part of a ‘‘botnet.’’ The ONI has monitored an increasing
number of just-in-time blocking incidences using DDoS attacks, going back to our first
acquaintance during the Kyrgyzstan parliamentary elections of 2005. In that episode,
the Web sites of opposition newspapers came under a debilitating attack that left
them unable to communicate during the critical period leading up to and during the
Kyrgyz election. 8 Since the Kyrgyz case, DDoS attacks have featured prominently in
the dispute between Russia and Estonia in May 2007, during the Russia-Georgia conflict of 2008, and in numerous cases involving the Web sites of human rights and political opposition groups.
These tactics are particularly difficult to monitor using traditional ONI methods
because of their temporary and fleeting duration, and because their perpetrators can
disguise their involvement through distribution and anonymity. Today, organized
criminal networks operate commercial botnets with significant powers of disruption.
Perpetrators can simply contract out a DDoS attack and benefit by the convenience of
an electronic assault that from the outside may look as though it is a random attack or
a series of unfortunate network errors. Attributing such attacks to their source is difficult because the vectors are distributed and the transactions are done through criminal
activity and illicit shadow markets. Although much of what the ONI has observed in
terms of computer network attacks and just-in-time blocking has occurred in the developing world, it is noteworthy the military use of botnets is being debated in NATO
countries and elsewhere. 9 The prospect of an arms race in cyberspace looms large.
Among many countries in the industrialized world, a major impetus to filter is the
desire to control access to information relating to the sexual exploitation of children,
otherwise known as child pornography. In almost all countries, possession and distribution of child pornography is illegal. In some countries, laws have been enacted to
restrict distribution of child pornography online. In some countries, private ISPs have
entered into voluntary arrangements to filter access to lists of child pornographic material, while in others entire nationwide filtering schemes have been proposed. In all
cases, the proposals have been the subject of considerable public debate and controversy. Although only a few very extreme minority groups, such as libertarians, question the right to access child pornography, many have raised questions about the
transparency of the processes being followed or the mechanisms put in place for oversight and review. For the ONI, for example, the mere test for access to this material is
prohibited because a simple connection to such a site would constitute a crime in most
jurisdictions. This situation leaves many researchers in a quandary as to how to verify
8
Ronald Deibert and Rafal Rohozinski
