Monday, February 13, 2012


Features

North Korea Suspected In Cyberoffensive Against U.S., South Korea

Another detail that has raised suspicions about North Korea is the fact that the attacks on South Korea proliferated on July 8, the 15th anniversary of North Korean leader Kim Il Sung's death (here being celebrated in Pyongyang).
TEXT SIZE - +
By Ron Synovitz
Computer security experts in the United States say dozens of U.S. government websites have been targeted in a coordinated cyberattack that also has struck key websites in South Korea since July 4-5.

The so-called denial-of-service (DOS) attacks are being called the most widespread cyberoffensive in recent years. They began on July 4 when 14 major websites in the United States were targeted -- including those of the White House, the U.S. State Department, and the New York Stock Exchange.

Since the night of July 7, access to at least 11 major South Korean websites has been cut or slowed dramatically by the cyberattacks -- including the websites of the presidential Blue House, the Defense Ministry, the National Assembly, Shinhan Bank, the daily newspaper "Chosun Ilbo." and the top Internet portal Naver.com.

Although it stopped short of specifically identifying any suspected culprits, South Korea's National Intelligence Service has implicated North Korea or pro-North Korea groups.

The impact of the attacks is seen as negligible so far. There has not been an actual security breach. Nor has there been damage to the online infrastructure in the United States or South Korea. But experts say the attacks serve as a reminder that Pyongyang has been planning for cyberwarfare.

Kwon Tae-shin, chief of the office of South Korea's prime minister, told reporters in Seoul on July 9 that the government has had emergency talks on how to deter possible cyberattacks in the near future.

"Especially, there is some speculation that North Korea or its followers may be engaged in this cyberterror, and that a second, a third cyberattack can occur. Therefore, I think the government should establish overall cybersecurity measures for national security," he said.

'Botnet' Attacks

U.S. authorities have described the latest cyberoffensive as a series of "botnet" attacks -- a method similar to the DOS attacks that targeted Estonia in 2007 during a dispute with the Kremlin, and against Georgia last year during its conflict with Russia over South Ossetia.

Despite widespread allegations that the Kremlin had a direct role in those attacks on Estonia and Georgia, the allegations have never been proven.

Cyberwarfare expert Evgeny Morozov, a fellow at the Open Society Institute in New York, says it would be difficult to confirm that any hostile government is the source of a botnet attack.

That's because a botnet is created by a virus that can infiltrate millions of computers around the world before ordering them to send out a flood of simultaneous requests to view targeted websites.

"A botnet is usually composed of computers whose users are not aware that they are volunteering their computer power for the attack," Morozov says.

"The whole point of a botnet is to have, [for example,] 10 million computers send their signals to the target server all at once. This scale is crucial if you really want to take down a website. That's what happens in a typical cyberattack. It is much less glamorous than having hackers break into a server, deface it, and then steal data. What happens is just this overloading of their capacity with bogus requests."

Northern Defiance

North Korea has been working for the past decade to improve its computer-warfare capabilities. The technology to create a botnet attack is within the capabilities of North Korean computer experts.

And unlike cyberattacks blamed on Russian or Chinese state hackers -- where there may have been collusion with nongovernment computer experts -- it is assumed that computer activities coming out of North Korea are much more closely controlled by the government in Pyongyang.

Another detail that has raised suspicions about North Korea is the fact that the attacks on South Korea proliferated on July 8, the 15th anniversary of North Korean leader Kim Il Sung's death.

Last month, North Korea also warned of "high-tech war" against the South for spreading what it said was false information about its involvement in cyberattacks.

In fact, North Korea has been defiant in the face of international criticism over nuclear and missile tests that it is conducting in violation of UN Security Council resolutions. Some analysts speculate that a cyberoffensive could be part of Pyongyang's hard line of resistance to such criticism.

On July 4, as the cyberattacks were first surfacing in the United States, North Korea test-fired seven ballistic missiles into the Sea of Japan.

Last month, the UN Security Council passed a resolution expanding sanctions against North Korea in response to a May 25 nuclear test carried out by Pyongyang. A UN sanctions committee could blacklist more North Korean companies and individuals for supporting Pyongyang's nuclear and missile programs. That committee is due to complete its work by July 10.

Preparing Defenses

South Korean computer experts who have examined the latest botnet offensive say they expect attacks to focus on more South Korean targets ahead of that UN committee's deadline.

Ahnlab, South Korea's leading online security firm, is among several private companies in Seoul whose websites have been under attack. Cho Joo-bong, a senior researcher at Ahnlab, says it is difficult to know who is coordinating the attacks.

"In fact, nobody can figure out the attacker at this moment," Cho says. "All the assumptions are not verified yet. These attackers are continuously updating lists and ordering followers to attack cyberspace behind the scenes. So, nobody can say who is maneuvering all this."

Some analysts raise doubts about North Korea's involvement, saying it may instead be the work of industrial spies or pranksters. But that hasn't eased concerns in Washington.

U.S. and NATO defense officials have launched efforts to create a defensive system to protect their computer infrastructure from future cyberattacks. That effort includes a gathering of cyberwarfare experts in Estonia last month under the auspices of a NATO cyberdefense task force.
This forum has been closed.
Comment Sorting
Comments
     
by: john from: usa
July 09, 2009 14:25
I say its time to strike North Korea
Nuke them they are evil take them out now before they themselfs fire nukes our way

by: lisa from: google
July 09, 2009 15:02
I think we had better be praying for our country instead of concentrating on what n.korea is doing.How many kids have we aborted whether in the womb or out? If we do face their bombs maybe we should think about this.

by: Jeff from: USA
July 09, 2009 20:03
Yea Lisa, maybe we should ignore a hostile country that wants to launch deadly weapons that could destroy the planet. And let's force our pro-life views on others and see where that gets us. Oh, and BTW, which High School did you drop out of?

by: sean from: ct
July 09, 2009 21:18
Im sorry but Lisa's comment is just plain nonsense. North Korea and the nut job that runs this starved, Nuke driven country is a grave threat to the worlds security. Abortions is a seperate issue all in its own. NK sends a long range missle and hits California, Hawaii, or JAPAN and the worlds ecconomy will go in a downward spiral that will make the latest look like a discount day at Target.
And what if one of these weapons get into the hands of the Taliban? Do you really think that anyone will be concerned about abortions then?

by: david from: the world
July 10, 2009 00:32
this is pretty scary stuff. what's the point of missiles and cyberattacks? Are they trying to go to war with someone? and john, I don't think a whole entire country can be evil. probably just the leader and the government.

by: really old geezer
July 10, 2009 09:21
North Korea may not be the source of these attacks. Hackers have been doing similar botnet and DOS attacks for decades with little more than bragging rights or the thrill of "knowing" they have brought some major power to their knees as motivation. Often times these attacks can be traced to nothing more than a greasy teenager with a high I.Q. and no friends to speak of. One of my favorite virus groups back in the 80's was Phalcon-Skism and their very well known virus ezine called 40hex.

by: Andrew from: USA
July 13, 2009 22:40
Wow, that comment suggesting we should be more concerned of abortions in our country than the trigger happy maniacal led North korea popping out nukes is just simply ridiculous. Lets see, what sounds worse, a nuclear weapon that can destroy millions of lives for generations to come, simultaneously destroying the earths ozone layer, structural integrity of plates in the core, as well as possibly knocking our natural orbital path around the sun with one simply drop of a bomb, or Meanwhile, an abortion that would 99% save a baby from living a terrible underprivileged life most likely ending up in an orphanage or just plain being mistreated or dumped in a trashcan somewhere by its preteen mother... BTW what good is life if your surrounded by nuclear fallout? Please think before you talk! also in response to David's post, most likely the missiles being fired and cyberattacks were to be a pain in our butts on the day we celebrate our independence(july 4th is when most occured/started). basically to be an annoyance on our special day to show they have no respect for the USA. You CAN NOT have a irrational leader like Kim Jong-Il making rash decisions with his finger on the trigger behind an arsenal of nuclear weapons. end of story. i still cant believe abortions were brought up... lol wow. Unless your talking about "aborting" N.Korea, please shut uuuuup :)

Most Popular

               
 
 
 
 
Being Discussed Now

U.S. Hearing On Balochistan Raises Hackles, Awareness In Pakistan

Latest Comment (1 total)

akram: It shows why pakistanis mistrust americans,US has plan for balkanization of pakistan and ... More

Jolie Earns Serbian Scorn For War Film

Latest Comment (86 total)

Abdulmajid: Well said, e.t., and I appreciate very much your qualifying 1992-95 as the ... More

Iran To Make Nuclear Announcement

Latest Comment (13 total)

Ivan: @ Jack from Upper Siberia, he only Official connection is Russia=Syria=Iran=Hamas=Hizbolla More