Hackers often harness the combined power of thousands of virus-infected personal computers to pump out spam e-mail or disable targeted servers by overwhelming them with Internet traffic.
Now an Air Force colonel is suggesting the U.S. military build its own “botnet,” or network of remotely controlled computers, to be ready to attack the computer networks of foreign enemies.
The proposal Col. Charles Williamson III outlined in the May edition of the Armed Forces Journal highlights the creative cyberwarfare strategies being hashed out by the military as hackers abroad step up their attacks on U.S. government computer networks and others around the world.
“The days of the fortress are gone, even in cyberspace,” wrote Williamson, staff judge advocate for Air Force Intelligence in the Surveillance and Reconnaissance Agency at Lackland Air Force Base in Texas. “While America must harden itself in cyberspace, we cannot afford to let adversaries maneuver in that domain uncontested.”
The government wouldn’t build its botnet by infecting innocent people’s computers like criminal hackers, Williamson wrote. Instead, the military could use PCs it was going to throw away. And it could expand that botnet’s computing horsepower by implanting its code on other government computers.
Williamson’s commentary has ignited a debate in the computer security community about the wisdom of building a military botnet — and the government’s ability to control it. The tactic he suggests is called a distributed denial-of-service, or DDoS, attack.
It’s what was used last year by hackers in a three-week assault that crippled government and corporate computer networks in the small Baltic nation of Estonia, which is highly computer-savvy.
It’s frequently used by organized criminals to extort Web site owners, who end up paying up to keep their sites online, and by botnet operators to disrupt rivals.
Alan Paller, director of research for the SANS Institute, which operates the Internet Storm Center,…