Story written by:
How Vulnerable Is America to Online Attack?
The online assault that temporarily paralyzed the tiny Baltic nation of Estonia last spring may have been the first real battle inaugurating the era of cyber-warfare. But that attack was a relatively minor nuisance compared to what could be unleashed on the United States.
Experts are divided on how serious and how imminent the danger is, and even what form it might take. But no one disputes that our increasingly networked, digitally dependent society is vulnerable to online attacks that could have devastating real-world results. Malicious hackers and terrorist groups have already proved they can cause computer-based trouble - but the biggest threat by far is from other countries.
Estonia was hammered by a wave of what are called distributed denial of service attacks, which abundant evidence suggests were launched by Russian nationalists furious at the Estonian government's plans to take down a Soviet war memorial. In a DDoS attack, hackers use "botnets" - networks of surreptitiously commandeered computers - to bombard a target Web site with bogus requests for information, overwhelming its host computer and forcing the site to shut down.
The digital siege of Estonia was the first time that the Web sites of an entire country's government, media, and banking institutions had simultaneously come under such an attack. But DDoS onslaughts have been used many times for political ends. A rash of them hit American government sites after NATO bombed the Chinese Embassy in the former Yugoslavia in 1999. Hackers on both sides have struck enemy Web sites during the conflicts in Kashmir, Kosovo, Israel/Palestine, and elsewhere. Commercial sites are even more frequently targeted: In 2000, DDoS attacks by still-unknown assailants briefly shut down the Web sites of eBay, Amazon.com, and Yahoo.
"Today, if I want to attack some site, I can rent the botnet to do it and even hire someone to run the attack for me."
Wreaking such online havoc doesn't require much technical know-how. "Since 1999 we've seen the rise of a very sophisticated cyber underworld," says Jeffrey Hunker, chief of digital security for the Clinton administration. "Today, if I want to attack some site, I can rent the botnet to do it and even hire someone to run the attack for me."
Ultimately, though, all a DDoS attack can do is close down a website. That's penny-ante stuff compared to what could happen if hackers broke into the computers controlling parts of the national infrastructure and turned them into weapons - by opening a dam's floodgates, for instance, or shutting down an electric grid.
Breaking into those kinds of complex, digitally protected systems is far more difficult than just lobbing a DDoS attack at a Web site. But it can be done. In fact, it's already happened: In the last 10 years, hackers have shut down the air traffic communication system at a Massachusetts airport, taken control of the software that regulates the flow of natural gas in Russian pipelines, turned off the safety monitoring system at an Ohio nuclear plant, and forced a water treatment facility in Australia to dump thousands of gallons of raw sewage into local creeks.
A serious cyberattacker might launch similar such disruptions not instead of a conventional attack, but on top of one. "If you set off a bomb and then take down the phone systems, that would do a lot to add to the panic," says Clay Wilson, a specialist in technology and national defense with the Congressional Research Service.
Still, at this point, the possibility of a terrorist group like al Qaeda launching an attack through the Internet seems relatively remote. Such outfits do use the Net extensively to recruit members and spread propaganda, and there have been countless picayune attacks on Western Web sites by hackers claiming to be "e-jihadists." But no major terrorist outfit seems to have developed the skills to do much more than that - or perhaps just hasn't bothered to use them. "Terrorists' efforts are focused on explosives and other physical attacks," says Dorothy Denning, a cybersecurity expert at the Naval Postgraduate School. "That's where the emotional appeal comes from. You go to heaven for being a martyr. I don't know what you get for attacking Web sites."
The biggest potential threat is from other nations that have the human and technical resources to develop serious offensive digital capabilities. Russia, China and other countries acknowledge they are developing cyberwarfare methods (as is the US, of course). With that in mind, many of America's most critical government and military computer systems are kept physically disconnected from the Internet to keep them out of the reach of online intruders. Most of the rest are well protected, experts generally agree - but nothing's foolproof. "All systems run on software, and all software has defects and vulnerabilities," Hunker says.
Indeed, in 1998 US officials discovered that systems at NASA, the Pentagon and other federal agencies were being accessed from a computer in Russia. In 2005, the FBI found hackers prowling through hard drives at a number of military bases and defense contractors. Just last summer, the Pentagon shut down one of its computer networks for several days after it was penetrated by hackers widely believed to be connected to China's People's Liberation Army. Germany, France and Britain were also hit by digital intruders allegedly working for the Chinese military.
And those are just the cases we know about. "I doubt that China's cyberwarriors are just sitting around waiting for a war to start," says Richard Clarke, former top adviser on cybersecurity to President George W. Bush. "They could be exploring our systems and planting viruses without our knowing it. The difference between that and causing real world damage is only a few keystrokes."







Features RSS Feed







14 Comments

14 Posts
+ Add Comment
10.3.07 1:33 PM PDT
Ann Moore
Jaaaar! That's Estonian for the edge of the ice.
10.3.07 11:49 PM PDT
Brian
As usual, the US won't adequately prepare until it's too late. Our largest vulnerability is the openness of our society. We bristle against government oversight and intervention, and this instinct is a key in a democratic society. Unfortunately, it makes us very vulnerable to a coordinated attack by a malicious entity.
10.5.07 11:57 AM PDT
grace
hopfully by keeping everyone informed and educated we as Americans can prevent a major cyberattack from happening
10.10.07 7:03 PM PDT
To Ann Moore
No it is not. It is jäääär... Not 5 a's but 4 ä's.
10.11.07 4:43 AM PDT
Geoff Nicoletti
Everybody is missing the key point, and I contacted both the FBI and the CIA on it: you now have a war coming that is started from below, not above. It is not started by a prime minister, a king, a president; it is a war outside of the historical control of generals and armies. Groups of hackers will go back and forth between nations. What we have seen in Estonia and in the attack on Defense secretary Gates is not a matter of prevention of a certain kind of attack, but hat the weapons are outside of
a nation's control. I suggest powergrids, banks, utilities,military sites, etc. unhook from the NET or be on a backup net, or unhook. Why? We can't arrest those
outside of the country...we don't have control here...if groups of hackers go after groups of hackers. That is the coming war.
10.12.07 5:22 PM PDT
Brianna
The US will never do anything until its too late. But then again, I wouldn't doubt the US would fake a cyberattack on itself just to go into yet ANOTHER country and declare war. The US has done it twice, what makes us think they wouldn't do it again?
10.12.07 5:22 PM PDT
Brianna
The US will never do anything until its too late. But then again, I wouldn't doubt the US would fake a cyberattack on itself just to go into yet ANOTHER country and declare war. The US has done it twice, what makes us think they wouldn't do it again?
11.26.07 7:16 PM PST
Zac
Brianna's comments are opinionated, rather than facts (not to mention pretty biased.)
The US doesn't release all information to the public.
There have been network security courses for a long time now, training people to understand flaws in networks.
They [USA] most-likely have had a huge team specifically for network security and/or net wars. We can't say they do, but we definitely can't say they don't.
7.9.08 8:31 PM PDT
Robert
Computer hackers are basically computer terrorists. They can cause serious problems for the U.S. economy by breaking into corporate computer information systems. All of us must protect our personal computers from identity theft. As technology advances every year, so must our computer security. We must make sure these computer hackers never get into the U.S. military nuclear missile systems!
9.17.08 5:58 PM PDT
Margaret
Is there really protection from cyberattacks?
As soon as a new solution is put in place, the
hackers have revved up their efforts and have
found new ways to terrorize/harrass and cause
major headaches any time they want. Call me old
fashioned, I'm paranoid enough not to do any
financial transactions involving credit/bank or
other personal identifying numbers. Oh, I know some
day I'll have to choice but to comply but til then....
9.24.08 10:51 AM PDT
Taulant
"They don't know who invented the "Iternet!" " ...
10.14.08 12:35 PM PDT
nalc
they're computer crackers, not hackers people! why doesn't anyone know the difference?
11.5.08 6:36 PM PST
bessimer
Hackers are good, crackers are bad. Hackers test a network for vulnerabilities and fix them. Crackers attack a network with malicious intent to bring it down or to find important information.
12.27.08 7:11 PM PST
Dr. Alan
There is no way for anyone to stop the upcoming "cyber war" or; World War 3.0 the human race is not capable of comprehension beyond what is obvious. In addition there is no human in the planet capable of planting a successful blockage against certain Cracker groups. Ladies and Gentlemen : first you dream, then you believe in your dream, than you achieve it. And i have put together a Qc [quantum compressor] here at Cambridge which detects any DDoS, BLACKFOX, powerdown,you name it. But i shall not share it, because at this point money for me is no object, and i am regretful to inform you that no one on this planet can put together what i have. So this is an upcoming cyber fight which i will not stop, unless i am appointed Chief of staff, in military installation- "Nevada sec.2", WHICH for your knowledge, is a very promising position with virtually unlimited expirmental back up.
Post your comment