Feeds

Zombie PCs are for crimelord chumps: Fear clusters, says infosec ace

Big Data tech can be used for 'carpet bombing' the internet

High performance access to file storage

It may be possible for a "single dedicated attacker" to run an internet "carpet-bombing" attack by applying Big Data and distributed computing technologies, security researcher Alejandro Caceres warns.

The traditional botnet, or network of hijacked computers, has been used for distributed computing problems, such as Bitcoin mining or DDoS attacks, for years.

But now attacking hundreds of thousands or even millions of targets at once – such as IP addresses or web applications – can be done using cheap hardware, open-source tools and a standard internet connection.

An attacker could potentially run an attack using a distributed Hadoop cluster using either cloud services (such as Amazon's Elastic MapReduce) or commodity hardware, Caceres explained during a presentation at Def Con earlier this month.

The platform for the attack would be a cluster of machines or a cloud-based system rather than a botnet of compromised machines, said Caceres.

Botnets have been the main vector of cybercrime for more than a decade, so the possibility that a different approach might be brought into play is possibly as significant as when spammers switched from using open mail relays to malware-infected PCs.

"This is not using a botnet. Botnets are generally 'dumb' systems used for DDoS or other similar attacks using compromised systems," Caceres, owner of software development firm Hyperion Gray and founder of the PunkSPIDER project told El Reg.

"What I'm talking about here is building your own distributed cluster of machines at home or in the cloud and using them for highly coordinated, complex attacks," he added.

Potential attacks could be geared towards hacking websites, stealing data or spreading malware, among other possibilities.

'Extremely effective' in tests

During a presentation of his research at Def Con, Caceres explained how automated, distributed SQL injection tool might be run over an Apache Hadoop cluster. Tests showed this approach to be "extremely effective" against a large test bed of websites. "We were able to inject 61 targets in just 45 seconds (typically a SQL injection attack on a single target would take at least 1 minute if done in a non-distributed way)," Caceres explained.

Caceres also demonstrated two other open-source custom-written distributed computing attack tools during the same talk.

One of them is a new version of PunkSCAN (the scanner that powers PunkSPIDER) for distributed vulnerability location and reconnaissance. The second is PunkCRACK, a distributed password-cracker that can be used over a Hadoop cluster, and would be suitable for applications such as distributed post-exploitation analysis.

Leveraging "Big Data" technology allows us to greatly reduce the time required to conduct a well-coordinated attack on a large number of targets in general, according to Caceres.

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.