0% found this document useful (0 votes)
3 views8 pages

DDoS Attack Disrupts Karnataka's Kaveri 2.0

The document discusses a DDoS attack that disrupted Karnataka's Kaveri 2.0 digital platform for property registration, highlighting the challenges of cybersecurity in governance. It details the nature of DDoS attacks, their consequences, and mitigation strategies, while emphasizing the increasing frequency of such attacks on critical infrastructure. The document also mentions similar attacks on other platforms, underscoring the need for robust cybersecurity measures.

Uploaded by

Arindam Das
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views8 pages

DDoS Attack Disrupts Karnataka's Kaveri 2.0

The document discusses a DDoS attack that disrupted Karnataka's Kaveri 2.0 digital platform for property registration, highlighting the challenges of cybersecurity in governance. It details the nature of DDoS attacks, their consequences, and mitigation strategies, while emphasizing the increasing frequency of such attacks on critical infrastructure. The document also mentions similar attacks on other platforms, underscoring the need for robust cybersecurity measures.

Uploaded by

Arindam Das
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Hello everyone,

In this edition of People and Bytes, we explore how a DDoS


attack brought a key public digital platform to a halt — and
what it reveals about the growing challenges at the
intersection of technology, governance, and cybersecurity .
What actually happened to a govt. web-based portal
streamlining property registrations in Karnataka ?
Was X also a victim to a DDoS attack ?

What actually happened to this govt. web-based portal streamlining


property registrations in Karnataka ?
Was X also a victim to a DDoS attack ?

A DDoS attack, or Distributed Denial of Service attack, is a malicious


attempt to disrupt the normal traffic of a targeted server, service, or
network by overwhelming it with a flood of internet traffic.
Unlike Denial of Service DoS attack which involves a single source, a
DDoS attack uses multiple compromised systems infected with malware
to generate traffic. These systems are collectively known as botnet.

The attacker uses these devices to simultaneously send a massive volume


of requests to the target. This flood of traffic overwhelms the system’s
resources (like bandwidth, CPU, or memory), causing it to slow down,
crash, or become inaccessible to legitimate users.

Types of DDoS Attacks:

 Volume-based attacks: Overwhelm bandwidth (e.g., UDP floods,


ICMP floods).
 Protocol attacks: Exploit weaknesses in Layer 3/4 protocols (e.g.,
SYN floods).
 Application layer attacks: Target Layer 7 (e.g., HTTP floods that
mimic real user behavior).

DDoS attacks can have serious consequences, especially for businesses


and online services.

Service Downtime

 Websites and services go offline, making them inaccessible to


users.
 E.g., banks, e-commerce sites, or gaming servers can crash,
causing massive disruption.

Financial Loss

 Revenue loss due to downtime (especially for online businesses).


 Mitigation costs: Companies often spend heavily on DDoS
protection tools and recovery.
 Long attacks can also increase operational expenses (e.g.,
bandwidth usage).

Security Risks

 Sometimes used as a distraction while hackers carry out other


attacks (like data breaches).
 May expose vulnerabilities in infrastructure.

Customer Frustration & Loss of Trust

 Users may lose access to essential services (e.g., banking,


customer support).
 Can lead to reputation damage and loss of customer trust.

Brand and Reputation Damage

 Downtime and poor availability can hurt brand image, especially if


publicized.
 Media coverage or social media backlash can amplify the damage.

Legal and Compliance Issues

 If user data is compromised during or because of the attack, it can


lead to regulatory fines or legal action.

Kaveri 2.0, Karnataka's digital platform for property registration and


related services, experienced performance issues due to a Distributed
Denial of Service (DDoS) attack in early Dec 2024 and Jan 2025. This
attack overwhelmed the system with excessive traffic, causing
widespread outages across the state.

Fake user accounts were created and automated bots were employed to
generate excessive database queries. Officials traced the attack to 62
email accounts linked to 14 different IP addresses, showing
the distributed nature of the attack.

In January 2025, a similar attack occurred, during which citizen-side


users generated an unusually high volume of traffic for Encumbrance
Certificate searches — nearly 8 times the normal level.
The portal was inundated with approximately 6.2 Lakh malicious
requests within two hours from malicious users using random keywords
to perform searches. This surge in traffic crippled the portal, reducing
the number of registrations.

Recovery and Ongoing Challenges

 Restoration Efforts: Authorities, including the e-Governance


Department and technical experts, worked to mitigate the attack's
effects. By mid-February 2025, services were largely restored, with
daily registrations returning to normal levels .
 Persistent Issues: Despite restoration, users reported ongoing
technical glitches. Notably, there were problems with the
automatic transfer of data between Kaveri 2.0 and the Bhoomi
software, affecting services like the Right to Tenancy Certificate
(RTC) and Khata transfers.

 Cybercrime Investigation: A formal complaint was lodged with


cybercrime authorities, leading to an investigation under the
Information Technology Act, 2000, against unidentified attackers.
 Legal Community's Concerns: The Mangalore Bar Association
considered legal action due to persistent glitches, highlighting
issues like excessive documentation demands and misalignment of
execution dates in the software.

DDoS attacks can be mitigated using a combination of technical tools and


preventive strategies. Here are some effective ways to reduce the impact
of such attacks:

 Rate Limiting and Throttling


Set limits on how many requests a user or IP address can make in a
given time. This helps prevent the system from being overwhelmed
by excessive traffic.
 Use of Content Delivery Networks (CDNs)
CDNs like Cloudflare or Akamai distribute the load by serving
content from multiple servers. They also help in filtering out
malicious traffic before it reaches the main server.
 Web Application Firewall (WAF)
A WAF filters and blocks suspicious web traffic. It can prevent bots
and attackers from abusing specific functions like the
Encumbrance Certificate search.
 Real-time Monitoring and Anomaly Detection
Monitoring tools can detect unusual spikes in traffic and trigger
alerts or automatic responses to limit damage.
 Dedicated DDoS Protection Services
Services such as AWS Shield, Azure DDoS Protection, and Google
Cloud Armor provide robust protection by automatically detecting
and mitigating attacks.
 Infrastructure Hardening
Using load balancers and auto-scaling infrastructure ensures the
system can handle unexpected traffic spikes. Keeping systems
updated also reduces vulnerability.
 Incident Response Plan
Organizations should have a clear plan in place for responding to
DDoS attacks, including technical steps and communication
strategies.
 CAPTCHA and Bot Protection
Introducing user verification steps like CAPTCHA can help block
automated bots from accessing critical services.

The cyberattack crippled the Kaveri 2.0 portal, and registrations fell
significantly on February 1 and February 4. While the portal was
restored on February 5, the DDoS attack should serve as a wake-up call
for organisations, particularly government agencies, to prioritise
cybersecurity and implement robust mitigation strategies.

Rising Risk of Cyberattacks


Cybersecurity professionals have raised concerns over the increasing
frequency and complexity of DDoS attacks, particularly those aimed at
government systems and vital infrastructure. A recent study suggests
that, without robust cybersecurity measures, India could face as many as
17 trillion cyberattacks by 2047.

DDoS attacks are often driven by political or economic motives. For


example, in August 2024, Elon Musk’s platform X (formerly Twitter) was
hit by a large-scale DDoS attack, resulting in significant delays and
service outages. The timing of the attack—just before a planned
conversation between Musk and U.S. presidential candidate Donald
Trump—sparked fears about cyber interference in high-profile events.

A notable earlier instance occurred in 2015, when GitHub, owned by


Microsoft, was targeted by a botnet linked to China. The attack was
aimed at GitHub pages that hosted tools to bypass Chinese internet
censorship. Attackers exploited Baidu, China’s leading search engine, by
injecting malicious JavaScript into users’ browsers, which then
unknowingly sent a flood of traffic to GitHub, overwhelming its servers.
Let us first have a brief overview of this topic.

What is DDoS ?

A DDoS attack, or Distributed Denial of Service attack, is a malicious


attempt to disrupt the normal traffic of a targeted server, service,
or network by overwhelming it with a flood of internet traffic.

Unlike Denial of Service DoS attack which involves a single source, a DDoS
attack uses multiple compromised systems infected with malware to
generate traffic. These systems are collectively known as botnet.

The attacker uses these devices to simultaneously send a massive volume


of requests to the target. This flood of traffic overwhelms the system’s
resources (like bandwidth, CPU, or memory), causing it to slow down,
crash, or become inaccessible to legitimate users.

Minimize image
Edit image
Delete image

A general flow diagram of how the DDoS attacks work.

Types of DDoS Attacks:

 Volume-based attacks: Overwhelm bandwidth (e.g., UDP floods,


ICMP floods).
 Protocol attacks: Exploit weaknesses in Layer 3/4 protocols (e.g.,
SYN floods).
 Application layer attacks: Target Layer 7 (e.g., HTTP floods that
mimic real user behaviour).
DDoS attacks can have serious consequences, especially for
businesses and online services.

Service Downtime - Websites and services go offline, making them


inaccessible to users e.g, banks, e-commerce sites, or gaming servers can
crash, causing massive disruption.

Financial Loss - Revenue loss due to downtime (especially for online


businesses). Long attacks can also increase operational expenses (e.g.,
bandwidth usage).

Mitigation cost - Companies often spend heavily on DDoS protection tools


and recovery.

Security Risks - Sometimes used as a distraction while hackers carry out


other attacks (like data breaches), may expose vulnerabilities in
infrastructure.

Customer Frustration & Loss of Trust - Users may lose access to essential
services (e.g., banking, customer support), can lead to reputation damage
and loss of customer trust.

Brand and Reputation Damage - Downtime and poor availability can hurt
brand image, especially if publicized. Media coverage or social media
backlash can amplify the damage.

Legal and Compliance Issues - If user data is compromised during or


because of the attack, it can lead to regulatory fines or legal action.

Now lets dive into what has brought these into news once again

What actually happened in Kaveri 2.0 !

Kaveri 2.0, Karnataka's digital platform for property registration and


related services, experienced performance issues due to a Distributed
Denial of Service (DDoS) attack in early Dec 2024 and Jan 2025. This
attack overwhelmed the system with excessive traffic, causing
widespread outages across the state.

Fake user accounts were created and automated bots were employed to
generate excessive database queries. Officials traced the attack to 62
email accounts linked to 14 different IP addresses, showing
the distributed nature of the attack.

In January 2025, a similar attack occurred, during which citizen-side users


generated an unusually high volume of traffic for Encumbrance Certificate
searches — nearly 8 times the normal level.
The portal was inundated with approximately 6.2 Lakh malicious requests
within two hours from malicious users using random keywords to perform
searches. This surge in traffic crippled the portal, reducing the number of
registrations.

Recovery and Ongoing Challenges

 Restoration Efforts: Authorities, including the e-Governance


Department and technical experts, worked to mitigate the attack's
effects. By mid-February 2025, services were largely restored, with
daily registrations returning to normal levels .
 Persistent Issues: Despite restoration, users reported ongoing
technical glitches. Notably, there were problems with the automatic
transfer of data between Kaveri 2.0 and the Bhoomi software,
affecting services like the Right to Tenancy Certificate (RTC) and
Khata transfers.
 Cybercrime Investigation: A formal complaint was lodged with
cybercrime authorities, leading to an investigation under the
Information Technology Act, 2000, against unidentified attackers.
 Legal Community's Concerns: The Mangalore Bar Association
considered legal action due to persistent glitches, highlighting
issues like excessive documentation demands and misalignment of
execution dates in the software.

How can these attacks be mitigated ?

DDoS attacks can be mitigated using a combination of technical tools and


preventive strategies. Here are some effective ways to reduce the impact
of such attacks:

 Rate Limiting and Throttling Set limits on how many requests a user
or IP address can make in a given time. This helps prevent the
system from being overwhelmed by excessive traffic.
 Use of Content Delivery Networks (CDNs) CDNs like Cloudflare or
Akamai distribute the load by serving content from multiple servers.
They also help in filtering out malicious traffic before it reaches the
main server.
 Web Application Firewall (WAF) A WAF filters and blocks suspicious
web traffic. It can prevent bots and attackers from abusing specific
functions like the Encumbrance Certificate search.
 Real-time Monitoring and Anomaly Detection Monitoring tools can
detect unusual spikes in traffic and trigger alerts or automatic
responses to limit damage.
 Dedicated DDoS Protection Services Services such as AWS Shield,
Azure DDoS Protection, and Google Cloud Armor provide robust
protection by automatically detecting and mitigating attacks.
 Infrastructure Hardening Using load balancers and auto-scaling
infrastructure ensures the system can handle unexpected traffic
spikes. Keeping systems updated also reduces vulnerability.
 Incident Response Plan Organizations should have a clear plan in
place for responding to DDoS attacks, including technical steps and
communication strategies.
 CAPTCHA and Bot Protection Introducing user verification steps like
CAPTCHA can help block automated bots from accessing critical
services.

The cyberattack crippled the Kaveri 2.0 portal, and registrations fell
significantly on February 1 and February 4. While the portal was restored
on February 5, the DDoS attack should serve as a wake-up call for
organisations, particularly government agencies, to prioritise
cybersecurity and implement robust mitigation strategies.

Rising Risk of Cyberattacks

Cybersecurity professionals have raised concerns over the increasing


frequency and complexity of DDoS attacks, particularly those aimed at
government systems and vital infrastructure. A recent study suggests
that, without robust cybersecurity measures, India could face as many as
17 trillion cyberattacks by 2047.

DDoS attacks are often driven by political or economic motives. For


example, in August 2024, Elon Musk’s platform X (formerly Twitter) was
hit by a large-scale DDoS attack, resulting in significant delays and service
outages. The timing of the attack—just before a planned conversation
between Musk and U.S. presidential candidate Donald Trump—sparked
fears about cyber interference in high-profile events.

In another occasion, in 2015 Microsoft-owned code repository GitHub was


targeted by a China based botnet. The attack specifically aimed two
GitHub projects that provided tools to circumvent Chinese censorship. The
attack involved injecting malicious JavaScript code into the browsers of
visitors to Baidu, China's most popular search engine, and other sites
using Baidu's analytics services.

You might also like