Feeds

Botnets fuel internet DDoS insurgency

Attacks top 100Gbps for the first time

Beginner's guide to SSL certificates

Updated Distributed denial of service attacks topped 100Gbps for the first time last year, during which attempts to flood websites with junk traffic went mainstream.

Major incidents in 2010 included DDoS attacks associated with pro- and anti-WikiLeaks hackers and militias as well as hacking attacks linked to political turmoil in Burma and Sri Lanka, according to the latest annual study by DDoS mitigation experts Arbor Networks. The DDoS mitigation firm saw the maximum attack traffic in the most ferocious attack exceed 100Gbps1 for the first time last year.

Botnets of compromised PCs once again served as the launchpad of countless attacks. Website packet-flooding attacks and more sophisticated application-layer attacks have been the mainstay of such activity but last year attacks targeting telecoms services – DNS (Domain Name System), VoIP and IPv6 – became more commonplace, according to the report. In particular, attacks against DNS servers have increased, mainly because it is relatively easily to floor such servers (even in cases where they are correctly configured and even more so when config problems come into play). Taking out DNS services would leave a majority of surfers unable to reach a targeted website.

Both data centre and telecoms service providers told Arbor that application-layer DDoS attacks are leading to significant outages. In response, many service providers have set up stateful firewalls and intrusion prevention system (IPS) devices to protect data centre infrastructure. Unfortunately these devices can act as a bottleneck when deployed in front of web servers, becoming overwhelmed by even a moderately powerful DDoS assault. Nearly half (49 per cent) of enterprises or operators surveyed experienced a firewall or IPS outage as the result of a DDoS attack.

"Network operators are facing a global Internet insurgency driven by the ubiquity of botnets," said Roland Dobbins, solutions architect with Arbor Networks. "This has led to rapidly escalating DDoS attack size, frequency and sophistication. Adding to the challenges facing operators is the increasing number of attack vectors, including applications and services, not to mention the proliferation of mobile devices." ®

1 The 100Gbps DDoS attack reported by a survey respondent was a DNS reflection/amplification attack, made possible by a combination of a lack industry-standard best practice anti-spoofing policy enforcement at network edges, coupled with the misconfiguration of a large number of DNS servers around the internet as open recursors.

The victim was an ISP, a customer of one of the network operators who took part in the survey, Arbor Networks explains.

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting users from Firesheep and other Sidejacking attacks with SSL
Discussing the vulnerabilities inherent in Wi-Fi networks, and how using TLS/SSL for your entire site will assure security.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.