Feeds

Botnets fuel internet DDoS insurgency

Attacks top 100Gbps for the first time

SANS - Survey on application security programs

Updated Distributed denial of service attacks topped 100Gbps for the first time last year, during which attempts to flood websites with junk traffic went mainstream.

Major incidents in 2010 included DDoS attacks associated with pro- and anti-WikiLeaks hackers and militias as well as hacking attacks linked to political turmoil in Burma and Sri Lanka, according to the latest annual study by DDoS mitigation experts Arbor Networks. The DDoS mitigation firm saw the maximum attack traffic in the most ferocious attack exceed 100Gbps1 for the first time last year.

Botnets of compromised PCs once again served as the launchpad of countless attacks. Website packet-flooding attacks and more sophisticated application-layer attacks have been the mainstay of such activity but last year attacks targeting telecoms services – DNS (Domain Name System), VoIP and IPv6 – became more commonplace, according to the report. In particular, attacks against DNS servers have increased, mainly because it is relatively easily to floor such servers (even in cases where they are correctly configured and even more so when config problems come into play). Taking out DNS services would leave a majority of surfers unable to reach a targeted website.

Both data centre and telecoms service providers told Arbor that application-layer DDoS attacks are leading to significant outages. In response, many service providers have set up stateful firewalls and intrusion prevention system (IPS) devices to protect data centre infrastructure. Unfortunately these devices can act as a bottleneck when deployed in front of web servers, becoming overwhelmed by even a moderately powerful DDoS assault. Nearly half (49 per cent) of enterprises or operators surveyed experienced a firewall or IPS outage as the result of a DDoS attack.

"Network operators are facing a global Internet insurgency driven by the ubiquity of botnets," said Roland Dobbins, solutions architect with Arbor Networks. "This has led to rapidly escalating DDoS attack size, frequency and sophistication. Adding to the challenges facing operators is the increasing number of attack vectors, including applications and services, not to mention the proliferation of mobile devices." ®

1 The 100Gbps DDoS attack reported by a survey respondent was a DNS reflection/amplification attack, made possible by a combination of a lack industry-standard best practice anti-spoofing policy enforcement at network edges, coupled with the misconfiguration of a large number of DNS servers around the internet as open recursors.

The victim was an ISP, a customer of one of the network operators who took part in the survey, Arbor Networks explains.

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.