Feeds

AOL rebuts zombie network slur

Mr Clean

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

AOL has described a report which brands it as running the most zombie infected network on the internet as "meaningless" because it fails to take into account its large user base. Security firm Prolexic reports that AOL was the biggest single source of DDoS attacks over the last six months, accounting for 11.3 per cent of attacks in the US and 5.3 per cent worldwide.

But AOL spokesman Andrew Weinstein argues that its 21.7m US members meant it had 40 per cent of the US market, so figures from Prolexic that 11 per cent of hostile attacks monitored in the US can be traced back to AOL's network meant the ISP had a lower than industry average infection rate. Barrett Lyon, CTO of Prolexic, conceded that AOL had a point. "Our figures didn't take into account per-capita user base but regardless more computers on AOL are attacking online sites than from any other network. Just because a home user subscribes to a reputable brand doesn’t mean they’re safe from the online criminal fraternity."

DDoS attacks are often launched from machines compromised by malware such as Agobot and Spybot that turn them into drones on zombie attack networks (AKA botnets). Access to these botnets is sold online to spammers, cyber-extortionists or other ne'er do wells. When used in a DDoS attack, these compromised machines can 'flood' a network with fake packets, preventing legitimate traffic from accessing a site.

The disruption compromised Windows PCs cause to the wider internet is a recognised problem. Recently, internet firms banded to together in an industry wide push dubbed Operation Spam Zombies to wipe zombies off the net. AOL is a leading member of this initiative. It has also placed increased emphasis on consumer security in its recent software releases.

Prolexic, a 30 strong security start-up based in Miami, said its report highlighted a significant change in the way DDoS attacks are being coordinated. Instead of focusing on Layer-3 TCP attacks, hackers are increasingly trying "advanced full connection based flood" attacks. This trend allowed it to discount spoofing (forged destination) assaults before considering the origin of the attacks its customer face, according to Prolexic's Lyon. ®

Related stories

UK under cyber blitz
Corporates focus on basics for IT security defences
Online gamers targeted in Korean MSN hack attack
Hackers plot to create massive botnet
ISPs urged to throttle spam zombies

Choosing a cloud hosting partner with confidence

More from The Register

next story
UK smart meters arrive in 2020. Hackers have ALREADY found a flaw
Energy summit bods warned of free energy bonanza
DRUPAL-OPCALYPSE! Devs say best assume your CMS is owned
SQLi hole was hit hard, fast, and before most admins knew it needed patching
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Mozilla releases geolocating WiFi sniffer for Android
As if the civilians who never change access point passwords will ever opt out of this one
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.