mously, with no demands being made, and presents investigators with the difficult task of pinpointing the source of the attack, which in at least one case was purchased from rogue hackers on the open market (in the CIS). During the Kyrgyz 2005 elections, a sophisticated DoS
attack was carried out against a national ISP (El Cat) that hosted several independent (and
pro-opposition) media sites. ‘‘Extortion notes’’ requiring that the ISPs remove the opposition
sites accompanied the attacks. El Cat was particularly vulnerable as it was dependent on a
few relatively ‘‘narrow’’ connections to the Internet and, as a result, the DoS attacks on the opposition sites threatened to disrupt access to all its other commercial Internet operations,
which included a large number of commercial clients. In Belarus, DoS attacks were used
against several opposition Web sites (hosted outside of Belarus). In this latter case, the
attacks were not accompanied by any claims of responsibility or demands. The attacks did
end shortly after the elections, as it was clear that the opposition was defeated and its street
protest would not prevail.
This later form of just-in-time blocking, which takes an offensive rather than defensive character (as in most traditional forms of filtering), is likely to gain in popularity. The expansion of
broadband access, particularly in less-developed countries with lower levels of knowledge of
‘‘bot nets’’ and other ‘‘crack attacks,’’ will almost certainly lead to an increase in these kind
of disruptions as ‘‘bot herders’’ exploit unprotected computers and broadband connections.
Other factors also make this form of offensive blocking particularly appealing. The first is that
such attacks are difficult to trace to an exact source (particularly as they can be bought) and
thus allow for ‘‘plausible deniability.’’ It is also difficult for individuals or nonstate groups to get
assistance in tracking down the source of such attacks, as they do not have access to the
necessary legal instruments to do so. For example, in the Kyrgyz election case, the extortion
notes sent by the attackers originated from a computer located in the United States. However,
to enlist U.S. authorities’ assistance, the means to do so—Multilateral Legal Assistance Treaties (MLATs)—need to be initiated by states. In this case, the Kyrgyz ISP affected by the
attacks was told that in order to get help from the FBI (or other U.S. law enforcement
agencies) they would either have to launch a request through the Kyrgyz Ministry of Justice
(or Interior), or file a civil case directly in a U.S. state court in which the computer allegedly responsible for sending the letter was located. In both cases, bureaucratic realities and costs
prevented the Kyrgyz ISP from taking any further action. These barriers, combined with the relative ease in which such attacks can be ‘‘plausibly denied’’ by their perpetrators, make them a
potentially effective tool for preemptive attacks against information resources. Indeed, use of
these kinds of attacks against ‘‘terrorist’’ sites is currently under active consideration by a
number of states, including perhaps most importantly the United States.
40
Indirect filtering by way of DoS or other computer network attacks (CNAs) also requires
much less in the way of infrastructure, and is thus less costly and less difficult to maintain
than national firewalls. As a result, it opens the door for substate actors to engage in their
own denial of access campaigns using CNAs. In the Russian Federation, and the CIS, for
Global Civil Society and the Securitization of the Internet
145
attack was carried out against a national ISP (El Cat) that hosted several independent (and
pro-opposition) media sites. ‘‘Extortion notes’’ requiring that the ISPs remove the opposition
sites accompanied the attacks. El Cat was particularly vulnerable as it was dependent on a
few relatively ‘‘narrow’’ connections to the Internet and, as a result, the DoS attacks on the opposition sites threatened to disrupt access to all its other commercial Internet operations,
which included a large number of commercial clients. In Belarus, DoS attacks were used
against several opposition Web sites (hosted outside of Belarus). In this latter case, the
attacks were not accompanied by any claims of responsibility or demands. The attacks did
end shortly after the elections, as it was clear that the opposition was defeated and its street
protest would not prevail.
This later form of just-in-time blocking, which takes an offensive rather than defensive character (as in most traditional forms of filtering), is likely to gain in popularity. The expansion of
broadband access, particularly in less-developed countries with lower levels of knowledge of
‘‘bot nets’’ and other ‘‘crack attacks,’’ will almost certainly lead to an increase in these kind
of disruptions as ‘‘bot herders’’ exploit unprotected computers and broadband connections.
Other factors also make this form of offensive blocking particularly appealing. The first is that
such attacks are difficult to trace to an exact source (particularly as they can be bought) and
thus allow for ‘‘plausible deniability.’’ It is also difficult for individuals or nonstate groups to get
assistance in tracking down the source of such attacks, as they do not have access to the
necessary legal instruments to do so. For example, in the Kyrgyz election case, the extortion
notes sent by the attackers originated from a computer located in the United States. However,
to enlist U.S. authorities’ assistance, the means to do so—Multilateral Legal Assistance Treaties (MLATs)—need to be initiated by states. In this case, the Kyrgyz ISP affected by the
attacks was told that in order to get help from the FBI (or other U.S. law enforcement
agencies) they would either have to launch a request through the Kyrgyz Ministry of Justice
(or Interior), or file a civil case directly in a U.S. state court in which the computer allegedly responsible for sending the letter was located. In both cases, bureaucratic realities and costs
prevented the Kyrgyz ISP from taking any further action. These barriers, combined with the relative ease in which such attacks can be ‘‘plausibly denied’’ by their perpetrators, make them a
potentially effective tool for preemptive attacks against information resources. Indeed, use of
these kinds of attacks against ‘‘terrorist’’ sites is currently under active consideration by a
number of states, including perhaps most importantly the United States.
40
Indirect filtering by way of DoS or other computer network attacks (CNAs) also requires
much less in the way of infrastructure, and is thus less costly and less difficult to maintain
than national firewalls. As a result, it opens the door for substate actors to engage in their
own denial of access campaigns using CNAs. In the Russian Federation, and the CIS, for
Global Civil Society and the Securitization of the Internet
145
