Skip to main content

Learning from a Distributed Denial of Service Attack against a Legally Binding Electronic Election: Scenario, Operational Experience, Legal Consequences

  • Conference paper
Electronic Government and the Information Systems Perspective (EGOVIS 2011)

Abstract

E-voting is the stress point of e-government regarding security requirements. This paper discusses the first known distributed denial of service attack (DDoS) worldwide against a legally binding remote electronic voting channel. In particular, the security considerations, the topology of the attack, and the specific countermeasures are described. The focus of this paper is on analyzing the experience and providing lessons learned. The lessons based on the concrete experience of this case study have been classified by the legal, technical, and operational aspects for handling DDoS attacks against e-government. Furthermore the relationships and interactions between these three aspects are illustrated.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Jefferson, D., Rubin, A., Simons, B., Wagner, D.: A Security Analysis of the Secure Electronic Registration and Voting Experiment (SERVE) (January 2004), http://www.servesecurityreport.org/paper.pdf

  2. Office for Democratic Institutions and Human Rights: Republic of Estonia Parliamentary Elections March 4, 2007 OSCE/ODIHR Election Assessment Mission Report (June 2007)

    Google Scholar 

  3. Deming, W.E.: Out of the Crisis. MIT CAES, Cambridge (1986)

    Google Scholar 

  4. Krimmer, R., Lehner, C., Stangl, S., Varga, B., Stein, R., Wenda, G., Kozlik, J.: E Voting im Rahmen der Wahlen zur Österreichischen Hochschülerinnen- und Hochschülerschaft 2009. In: Hauser, W., Kostal, M. (eds.) Hochschulrecht 2009, Vienna, NWV, pp. 539–551 (2009)

    Google Scholar 

  5. Lehner, C.: Die Wahlen zur Österreichischen Hochschülerinnen- und Hochschülerschaft, Doctoral Dissertation at the University of Vienna (2010)

    Google Scholar 

  6. Schmidt, A., Langer, L., Buchmann, J., Volkamer, M.: Specification of a Voting Service Provider. In: Requirements Engineering for E-Voting Systems (RE-VOTE), pp. 9–18 (August 2010)

    Google Scholar 

  7. Gibson, J.P., Lallet, E., Raffy, J.-L.: Analysis of a Distributed e-Voting System Architecture against Quality of Service Requirements. In: The Third International Conference on Software Engineering Advances, pp. 58–64 (October 2008)

    Google Scholar 

  8. Forschungsgruppe Internetwahlen: Zweiter Zwischenbericht zum Projekt Strategische Initiative: Wahlen im Internet nach Abschluss der Wahlen zum Studierendenparlament der Universität Osnabrück am 2, Osnabrück, Germany (February 2000)

    Google Scholar 

  9. Faißt, M.: Stellungnahme der Österreichischen Hochschülerschaft anlässlich der Änderung des Bundesgesetzes über die Vertretung der Studierenden an den Universitäten – Hochschülerschaftsgesetz 1998 (May 15, 2000)

    Google Scholar 

  10. Krimmer, R.: Machbarkeitsstudie. Durchführung der Hochschülerinnen- und Hochschülerschaftswahlen mittels elektronischer Abstimmungsverfahren (2007)

    Google Scholar 

  11. Prosser, A., Kofler, R., Krimmer, R., Unger, M.-K.: The First Internet-Election in Austria. The Findings by E-Voting.at. Working Papers of the Institute for Information Processing, Nr. 04/2003 (2003), http://epub.wu-wien.ac.at/dyn/virlib/wp/mediate/epub-wu-01_574.pdf?ID=epub-wu-01_574

  12. Prosser, A., Kofler, R., Krimmer, R., Unger, M.-K.: E-Voting Wahltest zur Bundespräsidentschaftswahl 2004, Working Papers of the Institute for Information Processing, Nr. 01/2004 (2004), http://epub.wu-wien.ac.at/dyn/virlib/wp/mediate/epub-wu-01_714.pdf?ID=epub-wu-01_714

  13. Arbeitsgruppe E-Voting: Abschlussbericht zur voralg an Dr. Ernst Strasser, Austrian Federal Ministry of the Interior (2004), http://www.bmi.gv.at/cms/BMI_wahlen/wahlrecht/files/Abschlussbericht_E_Voting_2004_11_29.pdf

  14. Prosser, A., Steininger, R.: E-Voting2006.at. An Electronic Voting Test among Austrians abroad, Working paper Nr. 02/2006 (2005), http://epub.wu-wien.ac.at/dyn/virlib/wp/mediate/epub-wu-01_b8f.pdf?ID=epub-wu-01_b8f

  15. Prosser, A., Krimmer, R., Kofler, R.: Implementing an Internet-based Voting System for Public Elections. Project Experience. In: Camp, O., Filipe, J.B.L., Hammoudi, S., Piattini, M. (eds.) Enterprise Information Systems V, pp. 294–299. Kluwer Academic Publishing, Boston (2004)

    Google Scholar 

  16. APA: Wissenschaftsminister Hahn will E-Voting bereits bei ÖH-Wahl 2009. Aussendung APA0431, Vienna (May 11, 2007)

    Google Scholar 

  17. Austrian Head of Federation of Students: Bedenken der ÖH Bundesvertretung zu e-Voting bei Hochschülerinnen- und Hochschülerschaftswahlen (September 2007)

    Google Scholar 

  18. Alvarez, R., Hall, T.: Point, Click, and Vote. The Future of Internet Voting. Brookings Press, Washington, DC (2004)

    Google Scholar 

  19. Alvarez, R., Hall, T.: Electronic Elections. The Perils and Promise of Digital Democracy. Princeton University Press, Princeton (2008)

    Google Scholar 

  20. Austrian Ministry for Science and Research: E-Voting Evaluation Report. 2010. E-Voting bei den Hochschülerinnen- und Hochschülerschaftswahlen 2009–Evaluierungsbericht (2010)

    Google Scholar 

  21. Council of Europe: Recommendation Rec(2004)11 of the Committee of Ministers to Member States on Legal, Operational and Technical Standards for e-Voting (2004), https://wcd.coe.int/wcd/ViewDoc.jsp?id=778189

  22. Austrian Government (no date): Hochschülerinnen- und Hochschülerschaftsgesetz (HSG 1998) (1998) (Federation of Students law), http://www.bmwf.gv.at/startseite/hochschulen/universitaeten/gesetze/studienrecht/hsg_1998/

  23. Austrian Government (no date): Hochschülerinnen- und Hochschülerschaftswahlordnung (HSWO 2005) (2005) (Election Regulations), http://www.bmwf.gv.at/startseite/hochschulen/universitaeten/gesetze/studienrecht/hswo_2005/

  24. Austrian Government (no date): Bundesgesetz über elektronische Signaturen (Signaturgesetz - SigG) (Electronic Signature Law), http://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10003685

  25. A-SIT: Certificate According to §34 (6) HSG 1998 for the Federation of Students Election 2009 (2009), http://www.a-sit.at

  26. Austrian Government (no date): Strafgesetzbuch (StGB) (Criminal Code), http://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10002296

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2011 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Ehringfeld, A., Naber, L., Kappel, K., Fischer, G., Pichl, E., Grechenig, T. (2011). Learning from a Distributed Denial of Service Attack against a Legally Binding Electronic Election: Scenario, Operational Experience, Legal Consequences. In: Andersen, K.N., Francesconi, E., Grönlund, Å., van Engers, T.M. (eds) Electronic Government and the Information Systems Perspective. EGOVIS 2011. Lecture Notes in Computer Science, vol 6866. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-22961-9_5

Download citation

  • DOI: https://doi.org/10.1007/978-3-642-22961-9_5

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-642-22960-2

  • Online ISBN: 978-3-642-22961-9

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics