in this case—including an ongoing one by the ONI’s sister project, the Information
Warfare Monitor—and to date no definitive evidence has been found linking the attacks
to the Russian security forces.
Third-Generation Controls
Unlike the first two generations of content controls, third-generation controls take a
highly sophisticated, multidimensional approach to enhancing state control over national cyberspace and building capabilities for competing in informational space with potential adversaries and competitors. The key characteristic of third-generation controls
is that the focus is less on denying access than successfully competing with potential
threats through effective counterinformation campaigns that overwhelm, discredit, or
demoralize opponents. Third-generation controls also focus on the active use of surveillance and data mining as means to confuse and entrap opponents.
Third-generation controls include enhancing jurisdiction over national cyberspace
and expanding the powers of state surveillance. These include warrantless monitoring
of Internet users and usage. In 2008, Russia expanded the powers previously established by SORM-II, which obliged ISPs to purchase and install equipment that would
also permit local FSB offices to monitor the Internet activity of specific users. The new
legislation makes it possible to monitor all Internet traffic and personal usage without
specific warrants. The legislation effectively brings into the open covert powers that
were previously assigned to FAPSI, with the twist of transferring to the ISPs the entire
costs associated with installing the necessary equipment. The SORM-II law was widely
used as a model for similar legislation in other CIS counties, and it is expected that the
new law will likewise become a standard in the CIS. Although it is difficult to verify the
use of surveillance in specific incidences, inferences can be drawn from specific examples. In July 2008, a Moldovan court ordered the seizure of the personal computers of
12 individuals for allegedly posting critical comments against the governing party. The
people were accused of illegally inciting people ‘‘to overthrow the constitutional order’’
and ‘‘threaten the stability and territorial integrity of the Republic of Moldova.’’ It is
unknown how the authorities obtained the names of the people, but some suggest
that an ISP provided them with the IP addresses of the users. 30
Several CIS countries are also pursuing the creation of national cyberzones. Countries
such as Kazakhstan, Tajikistan, and Russia are investing heavily into expanding Internet access to schools. These institutions are being tied to special Internet connections,
which limit access only to resources found in the national Internet domain. These ‘‘national zones’’ are popular among some Tajik and Kazakh ISPs because they allow the
ISPs to provide low-cost connectivity, as traffic is essentially limited to the national
segment. In 2007, Russian authorities floated the idea of creating a separate Cyrillic
cyberzone, with its own domain space and addressing scheme. National cyberzones
Control and Subversion in Russian Cyberspace
27
Warfare Monitor—and to date no definitive evidence has been found linking the attacks
to the Russian security forces.
Third-Generation Controls
Unlike the first two generations of content controls, third-generation controls take a
highly sophisticated, multidimensional approach to enhancing state control over national cyberspace and building capabilities for competing in informational space with potential adversaries and competitors. The key characteristic of third-generation controls
is that the focus is less on denying access than successfully competing with potential
threats through effective counterinformation campaigns that overwhelm, discredit, or
demoralize opponents. Third-generation controls also focus on the active use of surveillance and data mining as means to confuse and entrap opponents.
Third-generation controls include enhancing jurisdiction over national cyberspace
and expanding the powers of state surveillance. These include warrantless monitoring
of Internet users and usage. In 2008, Russia expanded the powers previously established by SORM-II, which obliged ISPs to purchase and install equipment that would
also permit local FSB offices to monitor the Internet activity of specific users. The new
legislation makes it possible to monitor all Internet traffic and personal usage without
specific warrants. The legislation effectively brings into the open covert powers that
were previously assigned to FAPSI, with the twist of transferring to the ISPs the entire
costs associated with installing the necessary equipment. The SORM-II law was widely
used as a model for similar legislation in other CIS counties, and it is expected that the
new law will likewise become a standard in the CIS. Although it is difficult to verify the
use of surveillance in specific incidences, inferences can be drawn from specific examples. In July 2008, a Moldovan court ordered the seizure of the personal computers of
12 individuals for allegedly posting critical comments against the governing party. The
people were accused of illegally inciting people ‘‘to overthrow the constitutional order’’
and ‘‘threaten the stability and territorial integrity of the Republic of Moldova.’’ It is
unknown how the authorities obtained the names of the people, but some suggest
that an ISP provided them with the IP addresses of the users. 30
Several CIS countries are also pursuing the creation of national cyberzones. Countries
such as Kazakhstan, Tajikistan, and Russia are investing heavily into expanding Internet access to schools. These institutions are being tied to special Internet connections,
which limit access only to resources found in the national Internet domain. These ‘‘national zones’’ are popular among some Tajik and Kazakh ISPs because they allow the
ISPs to provide low-cost connectivity, as traffic is essentially limited to the national
segment. In 2007, Russian authorities floated the idea of creating a separate Cyrillic
cyberzone, with its own domain space and addressing scheme. National cyberzones
Control and Subversion in Russian Cyberspace
27
