Jump to content

Recommended Posts

Posted

DDOS attacks are a topic that is taught in the computing curriculum. The word "DDOS" is filtered on the NCA list(s) in Netsweeper filtering and so all web content is blocked.

 

I am completely divided as to whether I should suggest that we override this block. On the one hand, we have to ensure that the curriculum can be taught, and that generally involves being able to to read around and research the subject. On the other, it would probably provide too much instruction on how to perform a DDOS attack, and not just for example, read the WIKI entry on what a DDOS attack is.

 

How do others deal with this?

Posted

Cannot see the problem, maybe you can limit this to specific groups but what is going to prevent students looking when they are not on the school filtering system.

 

Surely we are not really saying they should go and do it but educating them on what it is etc.

  • Thanks 1
Posted
We did have one pupil that decided "in a very limited and specific way" that there was a practical exercise associated with it.....
  • Thanks 1
Posted (edited)

How much of the curriculum depends on this one part (DDOS) and how much is really necessary for them to research themselves?

 

Asking purely out of interest as we are not at that level, for our KS level it's only Scratch etc.

 

Could you provide a carefully worded 'research' document for them?

 

Agree with the 'they will just go and do it somewhere else' sentiment, but if you can craft the information in a way that satisfies the curriculum but doesn't pique anyone's interest too much...?

 

Of course if it is a success, next they'll want you teaching the lessons...

Edited by Koldov
  • Thanks 2
Posted (edited)

Do you block informational websites in regards to other crimes such as car theft, fraud, cattle rustling just incase the kids decide they want to partake? If not then DDOS information shouldn’t be blocked either. In my opinion they should be all treated equally.

 

If someone really wanted to do this, they would look it up on their own devices or at home. Blocking these sites might draw the attention that the IT teams aren’t fond of this topic…

Edited by FN-GM
  • Thanks 2
Posted
I think the issue here partly is that if the NCA are of the opinion it should be blocked, we shouldn't just outright go against that without a conversation first. This is that conversation.
  • Thanks 3
Posted
1st lesson kids: This is the internet... there is no 'discussion'... there is only opinion... (and a few facts - but as everything in life, even these are open to interpretation by the 'internet users' and are rarely if ever, taken into account)... Oh, look! Cat videos...
  • Thanks 1
Posted
Damn, it's those pesky cattle rustling kids again... I knew we should have blocked that search term in school! :p

 

My inspiration was from an episode of Life on Mars. The cops needed a reason to arrest a landlord of a Manchester City Centre pub and used that as reason.

  • Thanks 1
Posted (edited)

My perspective is basically this:

 

There is a complete and utter disconnect between what is, and I do think should be taught in the Computing curriculum and the NCA.

 

Maybe I'm joining up dots that don't exist, but stay with me...

 

This report from Graham Cluley (well known expert) https://www.bitdefender.com/blog/hotforsecurity/nine-year-old-kids-are-launching-ddos-attacks-against-schools/

 

The UK's National Crime Agency (NCA) has launched a new initiative with the hope of educating youngsters of the consequences of launching DDoS attacks.

 

A study by the NCA's National Cyber Crime Unit (NCCU) discovered that the number of Distributed Denial of Service (DDoS) attacks launched against school networks and websites has more doubled from 2019 to 2020.

 

According to the NCCU, many of the referrals were secondary school children, with the average being 15 years old, and the youngest just nine.

 

One theory is that youngsters can fall into denial-of-service attacks by firstly playing online games, and then falling into installing mods, hacks, and even remote access trojans to get the upperhand on their gaming rivals.

 

Research has suggested that many young students do not consider it "wrong" to disrupt other players' gaming experience because it is considered just "another way to win," their peers are doing it too, and they certainly do not believe that they are likely to get into any trouble with the law.

 

So how can the police convince youngsters that they shouldn't launch attacks against others - whether it be fellow gamers or school websites?

 

The initiative being rolled out by the NCA to over 2,000 primary and secondary schools in the UK, ahead of going live at further schools and colleges across the country, will see students who search for terms associated with cybercrime greeted with an access denied "block page."

 

The warning message aims to direct students to the Cyber Choices website, which provides information about the Computer Misuse Act, and the consequences of breaking cybercrime laws.

 

But it's not just a warning for those who search for "stresser" and "booter" services which provide an easy way to launch a DDoS attack against a school's network.

 

The campaign also aims to influence young people, who might be considering engaging in cybercrime, to feel motivated to exploit their technical prowess in an ethical career in the technology, gaming, or cybersecurity industries.

 

The NCA Report

https://www.nationalcrimeagency.gov.uk/news/rise-in-school-cyber-crime-attacks-sparks-nca-education-drive

 

Data from the National Crime Agency’s National Cyber Crime Unit (NCCU) shows there was a 107 per cent increase in reports from the police cyber prevent network of students as young as nine deploying DDoS (distributed denial of service) attacks from 2019 to 2020.

 

Many referrals into the NCCU’s Prevent team are for children of secondary school age, with the median age at 15 and the youngest at nine.

 

and

 

Now the NCA and Schools Broadband, part of the Talk Straight Group, have launched a new initiative aimed to educate students who search for terms associated with cyber crime on school computers.

 

Instead of reaching an access denied ‘block’ page, students will instead see a warning message and suggested redirection to the Cyber Choices website (http://www.cyberchoices.uk), which aims to educate children of all ages about the Computer Misuse Act, cyber crime and its consequences.

 

Often referrals involve the use of stresser or booster services. These services cause DDoS attacks, denying access to a network or website of an organisation, and can cause major disruption to schools and colleges.

 

The Police's Cyber Prevent Network is *sigh* https://cyberalarm.police.uk/

 

Police CyberAlarm will detect and provide regular reports of suspicious cyber activity and vulnerabilities enabling your business or organisation to identify and mitigate its cyber risks.

 

We can allow pupils to seach for DDOS (or other terms) by overriding the NCA filter categories, or even turn the categories off to allow the curriculum to be taught

 

If we get to the point where Cyberalarm HAS to be installed, and we know it picks out searches for DDOS and other curriculum relevant terms, I don't want to see any of our pupils (or anybody else's) being fingered by Plod for simply doing their school work.

 

Ultimately, the NCA and the Curriculum boards need to get together and sort this out maybe involving the school ISP's as well.

 

I also got some verbal abuse from a school ISP on Twitter when I mentioned this there some time ago.

Edited by sigma
  • Thanks 1
Posted (edited)
My inspiration was from an episode of Life on Mars. The cops needed a reason to arrest a landlord of a Manchester City Centre pub and used that as reason.

 

Sorry, went over my head as I've never watched it (OH is a big fan of it though and Ashes to Ashes).

 

I also got some verbal abuse from a school ISP on Twitter when I mentioned this there some time ago.

 

I hope said Shool ISP also offers free DDoS mitigation...

 

It's an interesting debate... for T&L (what to teach and when) but in general for all sorts of child-rearing questions. The more 'liberal minded' and the more 'conservative minded' to endlessly assert their opinion is correct (which is what the internet is for after all). You can say let them do what they want, they'll just do it anyway, or don't ever let them see anything 'wrong' until they are old enough to have a fully (in)formed sense of the world and all its beauty/horror/right/wrong/morality/immorality (and that just depends on who you ask)....

 

You can exaggerate either claim and take them to the nth degree, but there are some good points to both sides of each argument and I'm sure as always the 'truth is out there' somewhere in the middle.

 

I'm not entirely sure what benefit the teaching of 'hacking' actually has though (like teaching someone to drive and also teaching them the 'theory' of how to hot-wire a car)... and I believe there is some truth in saying that there are those children who have a certain interest in computing may well discover these sorts of things on their own. We certainly have never taught 'hacking' in the computing curriculum at our KS level and yet have had an incident where a pupil (year 5 or 6 I think) was found trying to plug in a USB loaded with 'hacking' tools.

 

But there is also a lot of truth in saying that exposure to certain aspects of life may well pique their interest in something that they never would have normally if they'd never heard of it (of course you could say that about learning Henry VIII cut the head of a few wives)... and (if we're being impartial) they will see worse on the news most days!

 

As for other crimes, those can take resources a lot of youngsters don't readily have (especially large scale fraud, being out at 2 a.m. for car theft/burglary, cattle rustling) not saying it's unheard of though... But a lot of children have time to sit unsupervised in their bedrooms with their laptops and instead of cat videos or stupid TikTok stunts, they decide to look up what they learnt at school that day!

 

"falling into installing mods, hacks"

 

OMG, think of the children!

 

Again, depends on the child as with most issues... I will actually be honest and blame the Half-Life mod Counterstike for my current career path in I.T. (not hacking, although I was tempted when I regularly got my A$$ handed to me on a plate)... The worst I did was change skins when playing on my own against bots.

Edited by Koldov
  • Thanks 1
Posted

@sigma

 

it's ultimately up to you if you wish to block or allow access to DDoS information. Our partnership with the NCA has so far been successful on a number of fronts which ultimately helps to protect schools against unwarranted attacks and also educates children on what's against the law.

 

There is a lot going on the background with various government departments trying to work together regarding security for schools whereas in the past it's been a bit disjointed.

 

As we're larger than most and an ISP with our own network, we've first-hand experience of this and work with a number of agencies to protect schools and children when online.

 

Dave

 

Dave

  • Thanks 1
Posted

You teach them that it's illegal, and what will happen if they do it.

 

Can't teach what IP addresses and ports are without pointing how why they need to be secured

 

Can't teach computer security without pen testing tools

 

Any time you're teaching programming you're teaching automation, by definition

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...