Feeds

Zombie PCs are for crimelord chumps: Fear clusters, says infosec ace

Big Data tech can be used for 'carpet bombing' the internet

The essential guide to IT transformation

It may be possible for a "single dedicated attacker" to run an internet "carpet-bombing" attack by applying Big Data and distributed computing technologies, security researcher Alejandro Caceres warns.

The traditional botnet, or network of hijacked computers, has been used for distributed computing problems, such as Bitcoin mining or DDoS attacks, for years.

But now attacking hundreds of thousands or even millions of targets at once – such as IP addresses or web applications – can be done using cheap hardware, open-source tools and a standard internet connection.

An attacker could potentially run an attack using a distributed Hadoop cluster using either cloud services (such as Amazon's Elastic MapReduce) or commodity hardware, Caceres explained during a presentation at Def Con earlier this month.

The platform for the attack would be a cluster of machines or a cloud-based system rather than a botnet of compromised machines, said Caceres.

Botnets have been the main vector of cybercrime for more than a decade, so the possibility that a different approach might be brought into play is possibly as significant as when spammers switched from using open mail relays to malware-infected PCs.

"This is not using a botnet. Botnets are generally 'dumb' systems used for DDoS or other similar attacks using compromised systems," Caceres, owner of software development firm Hyperion Gray and founder of the PunkSPIDER project told El Reg.

"What I'm talking about here is building your own distributed cluster of machines at home or in the cloud and using them for highly coordinated, complex attacks," he added.

Potential attacks could be geared towards hacking websites, stealing data or spreading malware, among other possibilities.

'Extremely effective' in tests

During a presentation of his research at Def Con, Caceres explained how automated, distributed SQL injection tool might be run over an Apache Hadoop cluster. Tests showed this approach to be "extremely effective" against a large test bed of websites. "We were able to inject 61 targets in just 45 seconds (typically a SQL injection attack on a single target would take at least 1 minute if done in a non-distributed way)," Caceres explained.

Caceres also demonstrated two other open-source custom-written distributed computing attack tools during the same talk.

One of them is a new version of PunkSCAN (the scanner that powers PunkSPIDER) for distributed vulnerability location and reconnaissance. The second is PunkCRACK, a distributed password-cracker that can be used over a Hadoop cluster, and would be suitable for applications such as distributed post-exploitation analysis.

Leveraging "Big Data" technology allows us to greatly reduce the time required to conduct a well-coordinated attack on a large number of targets in general, according to Caceres.

Next gen security for virtualised datacentres

More from The Register

next story
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Linux kernel devs made to finger their dongles before contributing code
Two-factor auth enabled for Kernel.org repositories
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.