- BlackBerry Storm vs. the iPhone
- Digg's Kevin Rose: "We have to do better"
- Blogger warns: "Nortel doesn't make it out alive"
- Financial quagmire bringing out the scammers
- Verizon plays with the wrong e-mail addresses
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Test your Web Filter | Value of WDS
Two months after much of Estonia's online infrastructure was targeted by an online attack, the U.S government is sending cyberinvestigators to help the Baltic state better understand what happened.
A representative from the U.S. Department of Homeland Security's US-CERT (U.S. Computer Emergency Response Team) division is heading to Estonia this week to help analyze the large volume of data that was generated by the attacks, said Gregory Garcia, assistant secretary for cyber security and telecommunications with the DHS. "We are sending someone from our organization ... to help them with forensic analysis and to do some additional training on how to secure their infrastructure," he said.
Additionally, a member of the U.S. Secret Service will be there to help with training on incident response and computer crime investigations, according to a DHS spokesman.
In April, a widespread DDOS (distributed denial of service) attack struck Estonia and affected government and banking Web sites. Early press reports linked the attacks to Russia, exacerbating tensions between the two countries, but investigators now say that it is unclear who exactly was behind the incident.
"The data that we have does not speak to who's behind it. There's no smoking gun," said Jose Nazario, senior security engineer with Arbor Networks Inc., who has studied the attacks.
Unlike other Internet conflicts, the Estonian attacks do not seem to have been backed by a particular hacking group, said Gadi Evron, a security evangelist with Beyond Security. "They were of immense variety [and came] from the population of the Russian-speaking blogosphere," he said via instant message.
Some attackers ran simple scripts on their PCs, while others trained sophisticated groups of botnet computers at the Estonian systems, Evron said. "Many of the attacks were from fake sources and compromised computers around the world," he added.
During the incident, several international organizations helped the tiny country repel the online attacks, Garcia said.
"This was -- at least in the aftermath -- a good news story in the sense that Estonia looked to NATO for assistance and together the NATO countries came to the aid of Estonia," Garcia said. "It showed that the relationships we have internationally and across the federal government are paying off so we can respond in real time to attacks that are happening."
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment