3 May 2024, Friday, 10:43
Support
the website
Sim Sim,
Charter 97!
Categories

Belarusian providers are involved in global wire-tapping

19

Experts registered the interception of global internet traffic by providers from Belarus and Iceland.

A monitoring company Renesys published the results of the research into several incidents when the internet traffic of financial institutions, governments and communication providers from the USA, South Korea, Germany, Czech Republic, Lithuania, Libya and Iran was redirected to remote regions under uncertain circumstances.

In the company experts’ opinion, the redirection of traffic allows not only to trace the data being transferred, but also to change it. Notable is that it can be done without the final user noticing.

Up until recently the possibility of a targeted MiTM-attack (Man-In-the-Middle) with the redirection of internet traffic through BGP (Border Gateway Protocol) was considered only theoretically, but Renesys’ experts managed to save the information of the specific packets routing during the attacks.

Since February 2013 21 cases of traffic redirection to the networks of Belarusian providers have been registered. From February through March the GlobalOneBel provider was used, then Beltelecom clients have been included since May. For example the traffic from Mexican Guadalajara to Washington did not go directly, but was redirected through another end of the planet, went through Belarus and came back to America.

Later the Icelandic provider Opin Kerfi started showing high activity acting by approximately the same scenario.

“A user, probably, is drinking his morning coffee sitting at home in Virginia’s respectable suburb and does not suspect that someone in Minsk looks through his web-surfing history”, - Renesys’ experts draw a picture.

Whereas everything is more or less clear about the registration of the unusual traffic redirection, then the very mechanism of such an attack, its executor and customers remain a mystery. Renesys admits that the change in the traffic routing could have happened due to some system mistake, but it would rather be that targeted MiTM-attacks with BGP internet traffic redirection have come from being a theoretical possibility to an actual threat.

Write your comment 19

Follow Charter97.org social media accounts