South Korea’s National Police Agency says North Korea was behind cyber attacks that targeted 30 major websites between March 3 and 5, according to local news reports.
Websites such as the presidential office and Financial Services Commission were brought down by the distributed denial of service (DDoS) attack.
A DDoS attack involves flooding a server with so many requests that it becomes clogged and cannot operate. This is typically done by harnessing a vast network of computers to send the traffic simultaneously and continuously.
Rather than buy and build the computers, hackers usually build this network by infecting PCs with illicit software. At the time of the attacks, local computer security firm AhnLab estimated around 50,000 PCs were involved.
A similar series of DDoS attacks targeted computers in South Korea in July 2009.
AhnLab agrees that March attack was carried out in a similar method to the 2009 attack. It has a fuller,more technical explanation of the attacks on its blog. But AhnLab doesn’t offer any suggestion as to the source of the attacks.
Websites such as the presidential office and Financial Services Commission were brought down by the distributed denial of service (DDoS) attack.
A DDoS attack involves flooding a server with so many requests that it becomes clogged and cannot operate. This is typically done by harnessing a vast network of computers to send the traffic simultaneously and continuously.
Rather than buy and build the computers, hackers usually build this network by infecting PCs with illicit software. At the time of the attacks, local computer security firm AhnLab estimated around 50,000 PCs were involved.
A similar series of DDoS attacks targeted computers in South Korea in July 2009.
“After closely probing a number of Web sites that carried malicious codes, zombie computers and overseas servers that ordered the attacks, the strikes are identical to those of July 7, 2009, in ways of organizing the attack and designing the malicious codes,” an official at the Cyber Terror Response Center of the National Police Agency (NPA) said. –Yonhap News (via Korea Herald), April 6, 2011.
AhnLab agrees that March attack was carried out in a similar method to the 2009 attack. It has a fuller,more technical explanation of the attacks on its blog. But AhnLab doesn’t offer any suggestion as to the source of the attacks.
A DDoS attack, like any sophisticated computer hack, is typically difficult to pin down. The infected PCs that carried out the attack were probably located in many countries, but they would have been keeping contact with one or more servers that signaled them when to start attacking.