Disruptive Cyberattacks
Introduction to Disruptive/Destructive Attacks
We will use the term disruptive cyberattack to refer to
a cyberattack against the integrity and availability properties (of the CIA triad) where the motivation of the attackers is primarily to disrupt the operations of the target organization in some way.
You will see other terminology used, for instance, “destructive cyberattack”. But it's very difficult to draw the line between mere “disruption” and “destruction”. For instance, a DDOS attack against a web server is rather clearly disruptive but not destructive. And an attack like the one against Sony, which made thousands of computers unusable, could readily be considered destructive. But what about an attack that modifies a website to display a pro-terrorist message? It's hard to argue that is really destructive, though in some sense it did “destroy” the data previously displayed on the website. In any case, it is easier to simply group all such attacks into a single category.
Disruptive attacks can vary dramatically in their complexity and effects. On one end of the spectrum is DDOS attacks, which are very simple to carry out if you have control of a botnet (or rent it from someone who does – yes, you can rent a botnet). Attacks like the one against HBGary Federal require a little more skill but are still basically simple attacks with little planning involved. Other attacks like the one against Sony are advanced persistent threats – it's just that the last step includes destructive actions as well as exfiltrating data.
Another disruptive attack we've already learned about was the attack against the Ukrainian electric utility.
The more sophisticated disruptive attacks almost always have an espionage component as well, because it is difficult to disrupt an organization's network without learning something about how the network functions. This is one of the facts that makes the true danger of espionage attacks difficult to gauge. For example, if attackers steal operating procedures from an electric utility, it could be that the attackers are stealing the information in order to copy those procedures for their own use or for sale. Or it could be that the attackers are stealing the information in order to find ways to launch a future disruptive attack against the utility.
Like espionage, disruptive attacks are not new because of cyberspace. DDOS attacks that keep customers from accessing a company's website are not much different than a sit-in or a person chained to an entry door. Defacing a website isn't much different than spray painting a sign. Even a more destructive attack like the one against Sony is not new. Though not nearly as common as it used to be, organizations are occasionally bombed by people who do not like what the organization is doing. In the 1960's and 70's, it was even common for the bombers to detonate the bomb in a time and place where property damage was expected but not personal injuries.
But like espionage, cyberspace has made disruptive attacks easier to carry out, and allows the
IT 238 Introduction to Cyberterrorism Central Washington University – ITAM
Introduction to Disruptive/Destructive Attacks 2
attackers to perform the attacks without being physically present.
IT 238 Introduction to Cyberterrorism Central Washington University – ITAM