{"id":"852d5a8a-26ea-4980-b9ed-4fd986991b84","arxiv_id":"2504.15592","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Web defacement and DDoS attacks targeting Israel spiked immediately after October 7, 2023, then faded within weeks, at lower intensity and with more pro-Palestinian attackers than in the Russia-Ukraine conflict.","lead":"This paper measures low-level cyberattacks during the Israel-Gaza conflict, finding a sharp but short-lived spike in web defacements and DDoS attacks after October 7, 2023. The activity was smaller and more one-sided than in the Russia-Ukraine war, with pro-Palestinian attackers dominating.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The 15–20x 'lower than Russia-Ukraine' DDoS comparison is not normalized for global UDP-amplification trends, so the lower-scale claim may reflect a 2022-to-2023 baseline decline rather than a conflict difference.","rationale":"The reader's weakest assumption concerns representativeness of the four data sources, especially for one-sidedness. That is a valid concern, and the paper's own caveats about UDP-only DDoS and the pro-Palestinian Telegram channel support it. However, the most load-bearing issue for the central claim's headline comparison is temporal confounding in the Russia-Ukraine comparison. The paper compares absolute 2023 honeypot counts to absolute 2022 counts without adjusting for known changes in the DDoS-for-hire ecosystem, and cites a takedown study using the same dataset. If global UDP-amplification volume declined between the two periods, the 'significantly lower' conclusion is not established. This is a concrete, testable issue, and it does not require distrusting the authors' data collection. The paper's descriptive statistics, within-period one-sidedness, and short-lived surge patterns are plausible and well-documented; the condition should be to normalize or bound the cross-period comparison before accepting the scale claim. I therefore keep the CONDITIONAL verdict and add this specific analytical requirement.","tokens_in":11598,"tokens_out":4022,"duration_ms":41032,"concrete_test":"Re-run the DDoS analysis using the same honeypot data, but express Israel/Palestine daily attack counts as a share of total honeypot attack volume (or of attacks to a matched control set of countries) in the Aug 2023–Jan 2024 window, and compute the same normalized series for Russia/Ukraine in the Feb–Jun 2022 window. Also report the number of active sensors and their geographic distribution in both periods. If the normalized Israel/Palestine-to-Russia/Ukraine ratio is close to 1, or if total UDP volume fell by a comparable 15–20x factor between 2022 and 2023, the lower-scale conclusion is confounded by global trends and should be qualified or removed.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"Section 4.2 compares absolute honeypot DDoS counts for Israel/Palestine in late 2023 with the roughly 600 attacks/day reported for Russia/Ukraine in early 2022 from the same UDP-amplification honeypot, concluding the Israel-Gaza scale was 15–20 times lower. This comparison is load-bearing for the abstract's claim that 'the scale of attacks... was both significantly lower' than in the Russia-Ukraine war. The paper does not control for changes in the honeypot's global baseline between 2022 and 2023. The same dataset was used in prior work [24] to measure the effects of a global takedown against DDoS-for-hire services in 2022–2023, which implies the absolute volume of UDP amplification attacks may have fallen substantially for reasons unrelated to the Israel-Gaza conflict. Without a difference-in-differences design, a ratio-to-baseline normalization, or a demonstration that the honeypot sensor set and global attack mix were stable, the observed 15–20x gap could be an artifact of broader market trends rather than evidence that this conflict produced less low-level attack activity. The one-sidedness finding is less affected by this confound because it is a within-period comparison, but the 'lower than Ukraine' headline is not yet secured.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper empirically studies low-level, non-state cyberattacks (web defacement and UDP-amplification DDoS) and hacking-community discussions during the Israel-Gaza conflict from August 2023 to January 2024, comparing these with the authors' prior findings for the Russia-Ukraine war. It uses four datasets: self-reported defacement archives, a UDP-amplification DDoS honeypot, the English-language HACK FORUMS, and two Telegram channels of the Cyber Army of Palestine. The authors report immediate but short-lived surges in defacements and DDoS attacks after the Hamas-led assault, a largely one-sided pattern with far more attacks on Israeli than Palestinian targets, and a rapid decline in both attacks and discussions within weeks. Statistical significance is assessed with Kruskal-Wallis tests, Dunn post-hoc tests, and effect sizes.","tokens_in":11959,"tokens_out":5397,"duration_ms":46745,"significance":"If the findings hold, the paper provides a useful, systematic, comparative look at how low-level cybercrime actors respond to a major armed conflict, extending the authors' earlier Russia-Ukraine study. The analysis is transparent about its statistical methods and makes all datasets and scripts available through a data-sharing agreement, which is a strength for reproducibility. The paper also highlights the rapid decay of engagement, a pattern consistent with prior work. However, the central comparative claims—that attack and discussion scale was 'significantly lower' than in the Russia-Ukraine war, and that the conflict was 'prominently one-sided'—rest on data sources with notable selection biases and on an absolute-count comparison that does not control for global baseline changes; these issues need to be addressed before the headline conclusions can be considered fully supported.","major_comments":[{"comment":"The claim that Israel-Gaza DDoS activity was 'an order of magnitude less (15–20 times)' than in the Russia-Ukraine conflict compares absolute honeypot counts from late 2023 with roughly 600 attacks/day from early 2022, without accounting for changes in the global UDP-amplification baseline between those periods. This is a load-bearing comparison for the abstract's statement that the scale of attacks was 'significantly lower' than in the Russia-Ukraine war. The same honeypot dataset was used in Ref. [24] to measure the effects of a global takedown of DDoS-for-hire services in 2022–2023, which implies that global UDP-amplification attack volumes may have fallen substantially for reasons unrelated to this conflict. Without a difference-in-differences design using a control group of non-conflict countries, a ratio-to-baseline normalization, or at least a demonstration that the honeypot sensor set and global attack mix were stable over the comparison period, the 15–20x gap could be an artifact of market trends rather than a conflict-specific difference. I recommend the authors either provide such a normalization or substantially soften the cross-conflict scale claim.","section":"Section 4.2, 'UDP Amplification DDoS Attacks'"},{"comment":"There is an internal inconsistency between the abstract and the reported forum data. The abstract states that 'The scale of attacks and discussions within the hacking community this time was both significantly lower than those during the early days of the Russia-Ukraine war,' but Section 5 reports that the Israel-Gaza surge 'peaked at a higher level but tailed off much faster than those previously seen in the Russia-Ukraine conflict (which peaked at around 140 but lasted for a few weeks [5])'. Concretely, the paper reports about 270 posts per day for Israel-Gaza versus about 140 for Russia-Ukraine. If 'scale' is meant to refer to cumulative volume over the entire conflict window, the paper must compute and present those totals; if it refers to peak intensity, the current statement is contradicted by the paper's own numbers. This needs to be resolved by either adding a proper cumulative comparison or revising the abstract and conclusion.","section":"Section 5, 'Discussions on HACK FORUMS'"},{"comment":"The conclusion that the conflict was 'prominently one-sided' rests on four data sources: self-reported defacement archives, a UDP-only DDoS honeypot, a single English-language forum, and a pro-Palestinian Telegram channel. The paper acknowledges these limitations in a general way, but does not quantify how much bias they could introduce. For instance, pro-Israeli attackers could be using TCP-based DDoS, private defacement methods, or non-English channels, all of which would be invisible to this data collection. The one-sidedness finding is within-period and therefore less affected by the baseline-trend confound, but it is still susceptible to source-selection bias. I recommend either triangulating with additional independent data (e.g., Cloudflare's HTTP DDoS observations, Arabic-language sources, or pro-Israeli channels) or explicitly restricting the conclusion to the studied data sources rather than presenting it as a general characterization of the conflict's cyber dimension.","section":"Sections 3.1 and 5 ('Web Defacements', 'UDP Amplification DDoS Attacks', 'Underground Forum Posts', 'Telegram Chats')"}],"minor_comments":[{"comment":"The text reads 'from 7 October to 31 October 2024' when it should be '2023' for the E2 era; please correct the typo.","section":"Section 3.2, 'Statistical Tests'"},{"comment":"The phrase 'significantly less than that against Russia' uses the word 'significantly' in a non-statistical sense; since no significance test across conflicts is reported, consider replacing it with 'substantially less' to avoid ambiguity.","section":"Section 4.1, 'Website Defacement Attacks'"},{"comment":"The sentence 'suggesting that the conflict is highly associated with the outbreak of attacks on Israel' uses causal-sounding language; I recommend 'associated with' to match the observational nature of the data.","section":"Section 4.1, 'Website Defacement Attacks'"},{"comment":"It would be helpful to state explicitly whether the same victim-country identification procedure (ccTLD, IP geolocation, AS geolocation excluding CDNs) was used in the earlier Russia-Ukraine study [5], to confirm the cross-conflict comparability of the defacement counts.","section":"Section 3.1, 'Web Defacements'"},{"comment":"The annotations in Figure 1 (e.g., the red star marking the Hamas strike and the textual comments) are useful, but the font is small; please ensure legibility and that the era boundaries E1/E2/E3 are clearly aligned with the time axis.","section":"Figure 1 and Table 1"},{"comment":"The statement '10–15 times less than the IT Army of Ukraine' is awkward; consider '10–15 times fewer subscribers'.","section":"Section 5, 'The Cyber Army of Palestine'"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The genuinely new thing here is the first dedicated academic measurement of low-level cyberattacks in the Israel-Gaza conflict across several independent data sources: self-reported defacement archives, a UDP amplification honeypot, HackForums, and pro-Palestinian Telegram channels. The main findings — an immediate but short-lived surge, and one-sidedness with far more attacks on Israeli than Palestinian targets — are well supported by the within-period comparisons. The statistical work is appropriate: Kruskal-Wallis with Dunn post-hoc and effect sizes, applied to daily counts, and the authors are reasonably explicit about what their data can and cannot see. This is a solid descriptive study, and the comparison to the prior Russia-Ukraine work is a useful extension rather than a rehash.\n\nThe soft spot that matters is the cross-conflict DDoS comparison. The paper states that Israel-Gaza DDoS volume was 15–20 times lower than in the early Russia-Ukraine war, based on absolute counts from the same honeypot two years apart. That gap is not normalized for the global decline in UDP amplification attacks, which the authors' own earlier work showed followed the 2022–2023 takedown of DDoS-for-hire services. So part of the observed 'lower' could be baseline drift, not a conflict-specific difference. This does not touch the one-sidedness finding, which is within-period, but it does weaken the abstract's scale claim as stated. A difference-in-differences comparison or a ratio-to-baseline normalization would fix it.\n\nOther limitations are smaller and mostly acknowledged: the defacement data are self-reported, the Telegram sample is only a pro-Palestinian channel, and the forum is one English-language site. These could bias the one-sidedness picture, though the magnitude is hard to gauge. The authors note the Palestine infrastructure asymmetry as a caveat, which is fair. The era boundaries are fixed to conflict events, which is reasonable for measuring an effect.\n\nWho gets value: cybercrime researchers, conflict monitoring people, and anyone studying non-state behavior in wartime. It deserves a serious referee; I would accept it and ask for the DDoS baseline normalization to be addressed, either by adding the analysis or by softening the claim. I would cite it for the Israel-Gaza measurements, with a caveat on the scale comparison.","headline":"Solid, honest measurement of low-level cyberattacks in Israel-Gaza, but the headline 'lower than Ukraine' rests on an unnormalized DDoS comparison across years.","tokens_in":12350,"tokens_out":1240,"would_cite":true,"duration_ms":13464,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Low-level cyberattacks in the Israel-Gaza conflict surged right after the October 7 assault but faded within weeks, and were an order of magnitude smaller and more one-sided than those seen during the Russia-Ukraine war.","keywords":["Israel-Gaza conflict","cyberattacks","web defacement","DDoS attacks","hacktivism","low-level cybercrime","hacking forums","Telegram"],"falsifier":"A researcher could test the claims by obtaining TCP-based DDoS logs, non-English hacking forums, or pro-Israeli Telegram channels for the same period; substantial pro-Israeli attacks or volumes comparable to the Russia-Ukraine conflict would falsify the paper's one-sidedness and scale conclusions. A cheaper check is counting defacements of Palestinian (.ps) sites in the same archives after the same de-duplication; a number far above 25 would undermine the asymmetry claim.","tokens_in":11352,"feed_emoji":"💻","tokens_out":6354,"duration_ms":52450,"temperature":0.7,"pith_summary":"This paper tries to establish what low-level, non-state cybercriminals and volunteer hacktivists actually did during the Israel-Gaza conflict, using quantitative measurements of web defacements, UDP-amplification DDoS attacks, hacking-forum discussions, and Telegram channels. It claims that attacks and war-related chatter jumped sharply within hours or days of the Hamas-led assault on 7 October 2023, but died down within a few weeks, echoing the short-lived 'spark' seen after the Russian invasion of Ukraine. It also claims that this conflict's low-level cyberwar was far smaller than Russia-Ukraine's, and overwhelmingly one-sided, with many pro-Palestinian actors targeting Israel and almost no attacks on Palestinian targets. A sympathetic reader would care because this is one of the first quantitative, longitudinal looks at how ordinary hacktivists and cybercrime actors respond to a major war, and it suggests that their contribution to conflict is real but transient.","feed_headline":"Cyberattacks in Israel-Gaza war peaked fast, then fizzled","feed_subtitle":"Attack surges after October 7 were far smaller and more one-sided than in the Russia-Ukraine war.","key_machinery":"The load-bearing mechanism is a multi-source measurement design combining four observational streams: self-reported defacement archives (over 105,000 records), a global UDP-amplification DDoS honeypot, a large English-language hacking forum, and two public Telegram channels of the Cyber Army of Palestine. Against these, the paper applies a three-era statistical comparison (before the war, the first month, and the following three months) using Kruskal-Wallis tests, a rank-based test for whether the three time periods differ, with Dunn's post-hoc comparisons and eta-squared effect sizes. This era-based design lets the authors attribute the observed spikes to the conflict and quantify both their size and their short duration.","core_discovery":"The central discovery is that low-level cyberattacks in the Israel-Gaza conflict followed the same 'diminishing spark' pattern the authors previously documented for Russia-Ukraine: a sudden, statistically significant surge in web defacements and DDoS attacks immediately after the war began, followed by a rapid decline to near-baseline within about a month. The scale was an order of magnitude smaller than in the Russia-Ukraine case, with 1,791 defacements on Israeli sites versus 25 on Palestinian sites and over 3,000 UDP-amplification DDoS hits on Israel versus about 600 on Palestine, and the attack direction was heavily one-sided: 559 defacements explicitly supported Palestine while only one supported Israel. Debate on hacking forums also spiked then collapsed, and the pro-Palestinian Cyber Army of Palestine's Telegram channel lost engagement within weeks. The paper interprets this as evidence that armed conflict reliably produces a brief burst of low-level hacking that fades as interest wanes, and that in this conflict the 'cyber front' was largely a pro-Palestinian phenomenon.","pith_inferences":["Editorial inference: the one-sidedness measured here likely understates pro-Israeli activity, because the data sources are asymmetric — the Telegram channel is pro-Palestinian, the forum is English-language, and the honeypot excludes TCP-based DDoS; the paper itself flags the infrastructure asymmetry but does not quantify this bias.","Editorial inference: the 'diminishing spark' pattern could be tested prospectively in the next major conflict; if it recurs with similar timing (peak within days, decay within weeks), it would support a general regularity of low-level cyber-conflict engagement.","Editorial inference: the paper's ratio of about 559 pro-Palestinian to 1 pro-Israeli defacement messages suggests that defacement archives may serve as a rough, real-time barometer of online political sympathy in a conflict, worth comparing with social-media hashtag data."],"forward_implications":["Future large armed conflicts can be expected to produce a brief, front-loaded burst of low-level cyberattacks and hacktivist chatter, followed by a rapid return toward baseline within weeks.","The Israel-Gaza conflict shows that low-level cyberwar can be strongly one-sided, so asymmetry in attack volume is not always a proxy for state capability.","The order-of-magnitude gap with the Russia-Ukraine conflict suggests that a country's cybercrime ecosystem and history of information operations shape how much volunteer hacking a war attracts.","Hacktivist groups such as the Cyber Army of Palestine can be created quickly but have short operational lifespans, with their coordination channels losing engagement within about a month."],"supporting_citations":[{"why":"Supplies the defacement-archive dataset, the DDoS honeypot analysis method, and the Russia-Ukraine baseline used for every comparison in the paper.","marker":"[5]"},{"why":"Describes the UDP-amplification DDoS honeypot network whose captured flows are the paper's DDoS dataset.","marker":"[22]"},{"why":"Supplies the underground-forum corpus used to measure war-related hacker discussions.","marker":"[25]"},{"why":"Provides an industry report on Israel-Hamas cyberattacks, used to corroborate the DDoS patterns and the one-sidedness finding.","marker":"[9]"},{"why":"Defines the eta-squared effect-size thresholds used to interpret the Kruskal-Wallis test results.","marker":"[27]"}],"fun_headline_variants":["One-sided cyberattacks spike then fade in Gaza war","Diminishing spark: Gaza cyberattacks surge then fizzle","Gaza war's cyberattacks: quick spike, tiny scale, one-sided","Cyber 'front' in Gaza war was small, brief, pro-Palestine"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The findings assume that defacement archives, a UDP-only DDoS honeypot, one English-language hacking forum, and one pro-Palestinian Telegram channel together represent the full landscape of low-level cyberattacks in this conflict.","fun_headline_variants_meta":{"raw":{"variants":["One-sided cyberattacks spike then fade in Gaza war","Diminishing spark: Gaza cyberattacks surge then fizzle","Gaza war's cyberattacks: quick spike, tiny scale, one-sided","Cyber 'front' in Gaza war was small, brief, pro-Palestine"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000834,"raw_usage":{"total_tokens":3626,"prompt_tokens":921,"completion_tokens":2705,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":537,"completion_tokens_details":{"reasoning_tokens":2626}},"tokens_in":537,"tokens_out":2705,"duration_ms":17495,"temperature":1.0,"reasoning_tokens":2626,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-16T11:21:41.881188+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A researcher could test the claims by obtaining TCP-based DDoS logs, non-English hacking forums, or pro-Israeli Telegram channels for the same period; substantial pro-Israeli attacks or volumes comparable to the Russia-Ukraine conflict would falsify the paper's one-sidedness and scale conclusions. A cheaper check is counting defacements of Palestinian (.ps) sites in the same archives after the same de-duplication; a number far above 25 would undermine the asymmetry claim.","supporting_citations":[{"cited_title":"Cyber Attacks in the Israel-Hamas War,","cited_arxiv_id":null,"evidence_quote":"Provides an industry report on Israel-Hamas cyberattacks, used to corroborate the DDoS patterns and the one-sidedness finding."},{"cited_title":"Miles and M","cited_arxiv_id":null,"evidence_quote":"Defines the eta-squared effect-size thresholds used to interpret the Kruskal-Wallis test results."}],"review_version":1}