With some opening shots in a cyber component to the war of nerves in the Ukraine already fired, security analysts today pondered what a full-fledged cyberwar in the region would look like.
"The propaganda war is already in full force," said Richard Stiennon, principal at security consulting firm IT-Harvest and a former analyst with Gartner, in an interview. "Pictures of people fleeing the Ukraine, that kind of thing, the usual stuff. But when it escalates to block access, that's when the big cyber guns will come out."
In a blog post earlier this week, Stiennon outlined how he expected the cyber aspect of the crisis between the Ukraine and Russia — the latter's forces have seized control of the Crimea, although top level Russian officials, including President Vladimir Putin, have vigorously denied it — to play out.
"This playbook has already been written," Stiennon wrote, referring to past cyberwar incidents in Estonia in April 2007 and Georgia in August 2008. The latter conflict escalated to a short shooting war between Russian and Georgian forces, and the essential annexation of some Georgian territory.
"If Putin sticks to his playbook, here is what can be expected about the time the shooting starts in Crimea," Stiennon added. "The 'information war' that is playing out now will escalate to website defacement and DDoS [distributed denial-of-service] attacks against government websites, new sites and prominent businesses in Ukraine. The purpose will be to silence Ukraine's side of the story during the chaos. Of the six fiber links into Ukraine, half connect to Russia. These will be cut off as they were in 2008 against Georgia."
Some of those steps have taken place, according to news reports from the area. Communications facilities in the Crimea have been seized and physically damaged, with reports claiming that the peninsular has been virtually cut off from the rest of the world's Internet. Ukrainian government officials' mobile phones have been attacked for snooping purposes, and both Ukrainian and Russian news sites have been defaced.
None of the moves thus far have equaled the attacks in the Estonian and Georgian conflicts, but Stiennon predicted they would surpass that pair of events if Russia moves military forces into the eastern Ukraine, or if open warfare erupts in the Crimea.
Initial cyber attacks, like those already happening, have historically been the purview of so-called "hacktivists," ad hoc groups of hackers, and the technological-astute and technological-ignorant from both sides. DDoS attacks, although crude and relying on brute force to take down websites, can be easily organized and conducted with free tools.
"Governments have no monopoly on these kinds of attacks," said John Pescatore, also formerly with Gartner but now director of emerging security trends at the SANS Institute, a security training organization.
Sign up for Computerworld eNewsletters.