Tag Archives: ddos-attacks

How To Select A Distributed Denial of Service ‘DDoS’ Mitigation Service

Late last month, two members of the hacker group LulzSec pleaded guilty to launching distributed denial-of-service (DDoS) attacks against entities ranging from the state of Arizona to Nintendo to the CIA. Yet despite extensive media coverage of such attacks, chief information security officers are still surprised when their companies get hit. This is not an unforeseeable lightning bolt from the blue, people. The cyber world is full of anonymous arsonists, and too many businesses are operating without a fire department on call. A few sprinklers won’t cut it when things flare out of control. Firewalls and intrusion-prevention system appliances are no substitute for specialized DDoS backup when an attack escalates. Proactively securing a mitigation service can be a good insurance policy–in fact, it’s better than insurance, which pays off only after damage is done. That’s because mitigation services are designed to prevent destruction from occurring in the first place. Not only can a mitigation service act as a deterrent–many attackers will move on to easier prey when they see an initial DDoS attack fail–but these providers have the capacity and expertise to rapidly scale DDoS countermeasures against coordinated, professional attacks. That can mean keeping your website online even under heavy bombardment. Big And Small Companies At Risk Denial-of-service attacks used to be something that happened to other people, those with high online visibility. Not anymore. “We’ve seen very small companies come to us and they can’t figure out why they’re under attack,” says Chris Richter, VP of security products and services at Savvis. They ask, “‘What have we done?’” Blame the proliferation of prepackaged DDoS toolkits, such as the Low Orbit Ion Cannon and Dirt Jumper, for the fact that no one’s safe. Like any brute-force tactic, DDoS relies on the fact that any attack, even the most rudimentary, repeated with sufficient volume and frequency, can effectively shut down a network or website. Botnets often span thousands or millions of systems worldwide; Akamai, for example, provides a real-time attack heat map. In early July, attack rates were almost 30% above normal, with hot spots in Delaware and Italy. Geographic dispersion, coupled with network traffic crafted to look like legitimate connections from normal users, makes DDoS attacks both extremely effective and difficult to defeat if you’re not an expert with the right tools. There are three main distributed denial-of-service categories: > > Volumetric attacks overwhelm WAN circuits with tens of gigabits per second of meaningless traffic–so-called ICMP or UDP floods. > > Layer 3 attacks abuse TCP. For example, SYN floods overload network equipment by starting but never completing thousands of TCP sessions using forged sender addresses. SYN floods can be in excess of 1 million packets per second, largely in response to the wider deployment of hardware countermeasures on firewalls and other security appliances, says Neal Quinn, COO of DDoS mitigation specialist Prolexic. > > Layer 7 floods use HTTP GET or POST requests to overload application and Web servers. From the attacker’s perspective, L7 exploits aren’t anonymous. The attacking client’s identity (IP address) is exposed because a TCP handshake must be completed. Attackers who use this approach consider the risk outweighed by the technique’s effectiveness at much lower volumes and the traffic’s stealthy nature. Requests are designed to look like normal Web traffic, factors that make L7 attacks hard to detect. Our InformationWeek 2012 Strategic Security Survey shows that the increasing sophistication of threats is the most-cited reason for worry among respondents who say their orgs are more vulnerable now than in 2011, and L7 attacks are certainly sophisticated. They’re also getting more common: Mark Teolis, founder and CEO of DOSarrest , a DDoS mitigation service, says 85% of the attacks his company sees have a Layer 7 component. Attackers leveraging L7 are often developers; they may do some reconnaissance on a website, looking for page requests that aren’t cacheable and are very CPU-intensive–things like filling a shopping cart, searching a database, or posting a complex form. Teolis says that a mere 2 to 3 Mbps increase in specially crafted L7 traffic can be crippling. “We’ve had gaming sites tell us they can handle 30,000 customers, but if 100 hit this one thing, it’ll bring down the entire site,” he says. Layer 7 attacks are tough to defeat not only because the incremental traffic is minimal, but because it mimics normal user behavior. Teolis has seen attacks where an individual bot may hit a site only once or twice an hour–but there are 20,000 bots involved. Conventional network security appliances just can’t handle that kind of scenario. And meanwhile, legitimate customers can’t reach your site. Why Us? The motivations for a DDoS attack are as varied as the perpetrators. For many, it’s just business, with targets strategically chosen by cyber criminals. Others are political–a prime example is LulzSec hitting the Arizona Department of Public Safety to protest the state’s strict immigration law, SB 1070. And for some, it’s just sport. Given this randomness, it’s impossible to predict the need for professional distributed denial-of-service mitigation. For example, Teolis says one of DOSarrest ‘s customers was the Dog Whisperer, that guru of man’s best friend. “If Cesar Millan can get attacked, anyone is fair game,” he says. Purchasing mitigation services requires the same kind of budgeting as any form of IT security: What you spend on controls should be proportional to the value of the data or website. So, while any organization with an online presence is at some risk, those with financial or reputational assets that could be seriously damaged by going dark should take DDoS mitigation most seriously. Everyone should take these preparatory steps. > > Do online reconnaissance: Follow what’s being said about your company online, particularly on public social networks, and look for chatter that might hint at extortion or hacktivism. Subscribe to security threat assessment reports covering the latest DDoS techniques and incidents. Prolexic is one source for threat advisories; US-CERT also has overviews, like this one on Anonymous. > > Heed threat mitigation recommendations: DDoS threat reports typically include details about the attack signature and recommended mitigation steps. For example, a recent Prolexic report on the High Orbit Ion Cannon identifies specific attack signatures, in this case HTTP requests, and content filter rules to block them. For L3/L4 attacks, incorporate these rules into your firewall; do likewise for L7 attacks if your firewall supports application-layer filtering. > > Have a communications strategy: Know what you’ll tell employees, customers, and the media should you be the victim of an attack. Don’t wait to make statements up on the fly. > > Have an emergency mitigation backup plan: Although most DDoS mitigation services operate on a monthly subscription basis, if you haven’t signed up and an attack overwhelms your defenses, at least know who you’re gonna call. Quinn and Teolis say their services can be operational and filtering DDoS traffic within minutes, though of course it will cost you. What To Look For In DDoS Mitigation At the risk of oversimplification, DDoS mitigation services are fundamentally remote network traffic filters. Once your system detects an attack affecting your network or servers, you redirect traffic to the service; the service filters out the junk and passes legitimate packets to their original destinations. In this sense, it’s like a cloud-based spam filter for websites. This traffic redirection, so-called on-ramping, is typically done via DNS. The mitigation provider creates a virtual IP address, the customer makes a DNS A record (hostname) change pointing to the remote VIPA, traffic flows through the mitigation provider’s filters, and the provider forwards only legitimate traffic on to the original site. Those facing attacks on multiple systems can divert entire subnets using Border Gateway Protocol advertisements, using Generic Routing Encapsulation tunneling to direct traffic to the mitigation provider. Advertising a new route to an entire address block protects an entire group of machines and, says Quinn, has the advantage of being asymmetrical, in that the mitigation service is used only for inbound traffic. The most important DDoS mitigation features are breadth of attack coverage, speed of service initiation (traffic on-ramping), and traffic capacity. Given the increasing popularity of application-layer attacks, any service should include both L3/4 and L7 mitigation technology. Services may segment features into proactive, before-the-attack monitoring and reactive, during-the-incident mitigation. Customers with monthly subscriptions should demand typical and maximum mitigation times–measured in minutes, not hours–backed up by a service-level agreement with teeth. Even those procuring emergency mitigation services should expect fairly rapid response. Most DDoS specialists staff operations centers 24/7. With DDoS mitigation, procrastination can be expensive. For those 70% of customers who first turn to DOSarrest in an emergency, the setup fee for the first month is around $3,500 to $4,000, depending on the complexity of the site. In contrast, an average monthly cost on a subscription basis is $700 per public-facing IP address. Filtered bandwidth is another way to differentiate between services. Some, like Prolexic, adopt an all-you-can-eat pricing model. For a flat fee per server, customers can use the service as often as they need with as much bandwidth as required. Others, like DOSarrest , keep the “use as often as you like” model but include only a certain amount of clean bandwidth (10 Mbps in its case) in the base subscription, charging extra for higher-bandwidth tiers. Teolis says 10 Mbps is sufficient for at least 90% of his company’s customers. A few services use a pricing model akin to an attorney’s retainer, with a low monthly subscription but hefty fees for each DDoS incident. Richter says Savvis is moving to this model, saying that customers want usage-based pricing that resembles other cloud services. Prolexic’s Quinn counters that this pricing structure leads to unpredictable bills. Bottom line, there’s a DDoS service to suit your tolerance for risk and budgetary volatility. Optional services available from some providers include postattack analysis and forensics (what happened, from where, and by whom) and access to a managed network reputation database that tracks active botnets and sites linked to fraudulent or criminal activity, a feature that facilitates automated blacklisting to help prevent attacks in the first place. Aside from looking at service features, evaluate each company’s technical expertise and track record. DDoS mitigation specialists, for whom this is a core business (or perhaps their only business) arguably have more experience and focus than Internet service providers or managed security providers for which DDoS mitigation is just a sideline. Not surprisingly, Quinn, whose company was among the first to offer DDoS mitigation as a service, suggests customers should make vendors show evidence that DDoS mitigation is something they do regularly, not as a rare occurrence. Make sure the service has highly qualified staff dedicated to the task. Ask whether the provider has experts available 24/7 and how long it will take to access someone with the technical ability and authority to work on your problem. Unfortunately there’s no rule of thumb for measuring the DDoS mitigation return on investment; it’s really a case-by-case calculation based on the financial value of the site being attacked. It relies on factors such as the cost in lost revenue or organizational reputation for every minute of downtime. Quinn cites a common analyst cost estimate, which Cisco also uses in its product marketing, of $30 million for a 24-hour outage at a large e-commerce site. There’s a cruel asymmetry to DDoS attacks: They can cost thousands to mitigate, inflict millions in damage, and yet attackers can launch them on the cheap. A small botnet can be rented for as little as $600 a month, meaning a serious, sustained attack against multiple targets can be pulled off for $5,000 or $10,000. With damages potentially two or three orders of magnitude higher than the DDoS mitigation costs, many organizations are finding mitigation a worthwhile investment. In fact, three-quarters of DOSarrest ‘s customers don’t wait for a DDoS attack to flip the switch, but permanently filter all of their traffic through the service. That makes sense, particularly if it’s a high-value or high-visibility site, if your traffic fits within the cap, or if you’re using an uncapped service like Prolexic. These services use the same sorts of colocation hosting centers where companies would typically house public-facing websites, and they do geographically distributed load balancing and traffic routing to multiple data centers. That makes the risk of downtime on the provider’s end minimal. And this approach could actually reduce WAN costs since it filters junk before it ever touches your systems. Recommendations If a mitigation service is too expensive, there are things IT can do to lower the exposure and limit the damage from DDoS attacks (discussed more in depth in our full report): 1. Fortify your edge network: Ensure that firewall and IDS systems have DoS features turned on, including things like dropping spoofed or malformed packets, setting SYN, ICMP, and UDP flood drop thresholds, limiting connections per server and client, and dynamically filtering and automatically blocking (at least for a short time) clients sending bad packets. 2. Develop a whitelist of known good external systems: These include business partner gateways, ISP links and cloud providers. This ensures that stringent edge filtering, whether done on your firewall or by a DDoS service, lets good traffic through. 3. Perform regular audits and reviews of your edge devices: Look for anomalies like bandwidth spikes. This works best if the data is centrally collected and analyzed across every device in your network. 4. Understand how to identify DDoS traffic: Research attack signatures and have someone on your network team who knows how to use a packet sniffer to discriminate between legitimate and DDoS traffic. 5. Prepare DNS: Lower the DNS TTL for public-facing Web servers, since these are most likely to be attacked. If you need to protect an entire server subnet, have a plan to readvertise BGP routes to a mitigation service. 6. Keep public Web servers off your enterprise ISP link: With Web servers being the most common DDoS target, Michael Davis, CEO of Savid Technologies and a regular InformationWeek contributor, recommends Web hosting with a vendor that doesn’t share your pipes. “Your website may be down, but at least the rest of your business is up,” says Davis. 7. Practice good server and application security hygiene: Layer 7 attacks exploit operating system and application security flaws, often using buffer overflows to inject attack code into SQL databases or Web servers, so keep systems patched. For DDoS protection please click here . Source: Darkreading

Continued here:
How To Select A Distributed Denial of Service ‘DDoS’ Mitigation Service

Legal blog site suffered Distributed Denial of Service ‘DDoS’ attack

When a blog that typically attracts 30,000 visitors a day is hit with 5.35 million, its operators had better have been prepared for what seems way too big to be called a spike. The popular SCOTUSblog, which provides news and information about the United States Supreme Court, was put to this test last week after the historic healthcare ruling and it passed with flying colors, thanks to months of planning and a willingness to spend $25,000. “We knew we needed to do whatever it took to make sure we were capable of handling what we knew would be the biggest day in this blog’s history,” says Max Mallory, deputy manager of the blog, who coordinates the IT. The massive traffic spike was somewhat of a perfect storm for SCOTUSblog, which Supreme Court litigator Tom Goldstein of the Washington, D.C., boutique Goldstein & Russell founded in 2002. Not only is the site a respected source of Supreme Court news and information, but in the days leading up to the ruling, buzz about the blog itself began picking up. President Barack Obama’s press secretary named SCOTUSblog as being one source White House officials would monitor to hear news from the court. When the news broke, two of the first media organizations to report it — Fox News and CNN — got the ruling wrong. Many media outlets cited SCOTUSblog as being the first to correctly report that the Supreme Court upheld the Affordable Care Act in a 5-4 decision. But even before “decision day,” as Mallory calls it, the small team at SCOTUSblog knew Thursday would put a lot of strain on the blog’s IT infrastructure. The first indications came during the health care arguments at the Supreme Court in March, when SCOTUSblog received almost 1 million page views over the three days of deliberations. The blog’s single server at Web hosting company Media Temple just couldn’t handle the traffic. “That was enough to crash our site at various points throughout those days and it just generally kept us slow for a majority of the time the arguments were going on,” Mallory says. In the weeks leading up to the decision, Mallory worked with a hired team of developers to optimize the website’s Java code, install the latest plugins and generally tune up the site. Mallory realized that wouldn’t be enough, though. No one knew for sure when the high court would release the most anticipated Supreme Court case in years, but each day it didn’t happen there was a greater chance it would come down the next day. Traffic steadily climbed leading up to the big day: The week before the ruling the site saw 70,000 visitors. Days before the decision, the site got 100,000. “It became clear we weren’t going to be able to handle the traffic we were expecting to see when the decision was issued,” Mallory says. A week before the decision, Mallory reached out to Sound Strategies, a website optimization company that works specifically with WordPress. The Sound Strategies team worked throughout the weekend recoding the SCOTUSblog site again, installing high-end caching plugins, checking for script conflicts and cleaning out old databases from previous plugins that had been removed. The team also installed Nginx, the open source Web server, to run on the Media Temple hardware. All of the improvements helped, but when the decision did not come on Tuesday, July 26, it became clear that Thursday, July 28, the last day of the court’s term, would be decision day. Mallory was getting worried: Earlier in the week SCOTUSblog suffered a distributed denial-of-service (DDOS) attack targeting the website. That couldn’t happen on Thursday, when the court would issue the ruling. “This was our time, it just had to work,” Mallory says. The night before decision day, Mallory and Sound Strategies took drastic measures. Mallory estimated the site could see between 200,000 and 500,000 hits the next day, so the group decided to purchase four additional servers from Media Temple, which Sound Strategies configured overnight. SCOTUSblog ended up with a solution Thursday morning that had a main server acting as a centralized host of SCOTUSblog, with four satellite servers hosting cached images of the website that were updated every six minutes. A live blog providing real-time updates — which was the first to correctly report the news — was hosted by CoveritLive, a live blogging service. As 10 a.m. EDT approached, the system began being put to the test. At 10:03, the site was handling 1,000 requests per second. By 10:04 it had reached 800,000 total page views. That number climbed to 1 million by 10:10, and by 10:30 the site had received 2.4 million hits. Because of the satellite caching, Mallory says, the site was loading faster during peak traffic than it ever had before. In post-mortem reviews, Sound Strategies engineers said they found evidence of two DDoS attacks, one at 9:45 a.m. and another at 10 a.m., which the servers were able to absorb. “We built this fortress that was used basically for two hours that morning,” Mallory says. “It worked and it never slowed down.” Since the healthcare decision, SCOTUSblog has seen higher-than-normal traffic, but nowhere near the 5 million page views the site amassed on the biggest day in the blog’s history. “It was a roller coaster,” Mallory says. “You can have the best analysis, the fastest, most accurate reporting, but if your website crashes and no one can see it that moment, it doesn’t matter.” Source: http://www.arnnet.com.au/article/429473/how_legal_blog_survived_traffic_tidal_wave_after_court_healthcare_ruling/?fp=4&fpid=1090891289

Read the original post:
Legal blog site suffered Distributed Denial of Service ‘DDoS’ attack

Banking Outage Prevention Tips

A series of fresh technology shutdowns this spring at banks around the world reveals the financial services industry still has a long way to go toward ensuring full up time for networks, as well as communicating with the public about why tech glitches have happened and what is being done about them. In May, Santander, Barclays and HSBC were all hit by digital banking outages. Some customers of Barclays and Santander were unable to access accounts online for a time near the end of the month, an outage blamed largely on end-of-the-month transaction volume. At HSBC, an IT hardware failure temporarily rendered ATMs unable to dispense cash or accept card payments in the U.K. Barclays and Santander both apologized for the outages though statements, while HSBC’s approach revealed both the power and peril of social media in such cases. HSBC’s PR office took to social media to communicate updates on the outage, and to also receive criticism about the outage (HSBC, Santander and Barclays did not return queries for comment). After an earlier outage in November, HSBC had set up a social monitoring team to be more proactive about communicating with the public about tech glitches, a move that seemed to have some positive impact, as not all of the Twitter and Facebook postings about the most recent outage were complaints. The basic task of making sure the rails are working, and smoothing things over with customers when systems invariably shut down, is an even more pressing matter considering the propensity for outrage to spread quickly among the public via new channels. “One thing that’s true about outages is we’re hearing more about them. The prevalence of social media use by irate customers and even employees makes these outages more publicized,” says Jacob Jegher, a senior analyst at Celent. Jegher says the use of social media for outage communication is tough – balancing the need to communicate with customers with internal tech propriety is easier said than done. “While it’s certainly not the institution’s job nor should it be their job to go into every technical detail, it’s helpful to provide some sort of consistent messaging with updates, so customers know that the bank is listening to them,” Jegher says. National Australia Bank, which suffered from a series of periodic online outages about a year ago that left millions of people unable to access paychecks, responded with new due diligence and communications programs. In an email response to BTN, National Australia Bank Chief Information Officer Adam Bennett said the bank has since reduced incident numbers by as much as 40 percent through a project that has aimed to improve testing. He said that if an incident does occur, the bank communicates via social media channels, with regular updates and individual responses to consumers where possible. The bank also issued an additional statement to BTN, saying “while the transaction and data demands on systems have grown exponentially in recent years led by online and mobile banking, the rate of incidents has steadily declined due to a culture of continuous improvement…The team tests and uses a range of business continuity plans. While we don’t disclose the specifics, whenever possible we will evoke these plans to allow the customer experience to continue uninterrupted.” While communicating information about outages is good, it’s obviously better to prevent them in the first place. Coastal Bank & Trust, a $66 million-asset community bank based in Wilmington, N.C., has outsourced its monitoring and recovery, using disaster recovery support from Safe Systems, a business continuity firm, to vet for outage threats, supply backup server support in the event of an outage, and contribute to the bank’s preparation and response to mandatory yearly penetration and vulnerability tests. “Safe Systems makes sure that the IP addresses are accessible and helps with those scans,” says Renee Rhodes, chief compliance and operations officer for Coastal Bank & Trust. The bank has also outsourced security monitoring to Gladiator, a Jack Henry enterprise security monitoring product that scours the bank’s IT network to flag activity that could indicate a potential outage or external attack. The security updates include weekly virus scans and patches. Coastal Bank & Trust’s size – it has only 13 employees – makes digital banking a must for competitive reasons, which increases both the threat of downtime and the burden of maintaining access. “We do mobile, remote deposit capture, all of the products that the largest banks have. I am a network administrator, and one of my co-workers is a security officer. With that being said, none of us has an IT background,” Rhodes says. “I don’t know if I could put a number on how important it is to have these systems up and running.” Much of the effort toward managing downtime risk is identifying and thwarting external threats that could render systems inoperable for a period of time. Troy Bradley, chief technology officer at FIS, says the tech firm has noticed an increase in external denial of service attacks recently, which is putting the entire banking and financial services technology industries on alert for outage and tech issues with online banking and other platforms. “You’ll see a lot of service providers spending time on this. It’s not the only continuity requirement to solve, but it’s one of the larger ones,” he says. To mitigate downtime risk for its hosted solutions, FIS uses virtualization to backstop the servers that run financial applications, such as web banking or mobile banking. That creates a “copy” of that server for redundancy purposes, and that copy can be moved to another data center if necessary. “We can host the URL (that runs the web enabled service on behalf of the bank) at any data center…if we need to move the service or host it across multiple data centers we can do that…we think we have enough bandwidth across these data centers to [deal with] any kind of denial of service attack that a crook can come up with,” Bradley says. FIS also uses third party software to monitor activity at its data centers in Brown Deer, WI; Little Rock and Phoenix, searching for patterns that can anticipate a denial of service attack early and allow traffic connected to its clients to be routed to one of the other two data centers. For licensed solutions, FIS sells added middleware that performs a similar function, creating a redundant copy of a financial service that can be stored and accessed in the case of an emergency. Stephanie Balaouras, a vice president and research director for security and risk at Forrester Research, says virtualization is a good way to mitigate both performance issues, such as systems being overwhelmed by the volume of customer transactions, and operational issues such as hardware failure, software failure, or human error. “If it’s [performance], the bank needs to revisit its bandwidth and performance capacity. With technologies like server virtualization, it shouldn’t be all that difficult for a large bank to bring additional capacity online in advance of peak periods or specific sales and marketing campaigns that would increase traffic to the site. The same technology would also allow the bank to load-balance performance across all of its servers – non-disruptively. The technology is never really the main challenge, it tends to be the level of maturity and sophistication of the IT processes for capacity planning, performance management, incident management, automation, etc.,” she says. In the case of operational issues, server virtualization is still a great technology, Balaouras says, adding it allows the bank to restart failed workloads within minutes to alternate physical servers in the environment or even to another other data center. “You can also configure virtual servers in high-availability or fault-tolerant pairs across physical servers so that one hardware failure cannot take down a mission-critical application or service,” Balaouras says. Balaouras says more significant operational failures, such as a storage area network (SAN) failure, pose a greater challenge to network continuity and back up efforts. “In this case, you would need to recover from a backup. But more than likely a bank should treat this as ‘disaster’ and failover operations to another data center where there is redundant IT infrastructure,” she says. Source: http://www.americanbanker.com/btn/25_7/online-banking-outage-prevention-strategies-1050405-1.html

View article:
Banking Outage Prevention Tips

UFC.com hit with Distributed Denial of Service ‘DDoS’ attack

The FBI was instrumental in arresting two dozen hackers this week that allegedly bought and sold credit card numbers over the Web. If you ask Ultimate Fighting Championship President Dana White, though, he had something to do with it too. Of the 24 individuals apprehended by the Federal Bureau of Investigation this week as part of a two-year undercover sting, at least one wasn’t limiting himself to only computer crimes linked to credit fraud. Mir Islam, 18, was arrested on Tuesday for allegedly selling stolen credit card info on an FBI-run website, according to the United States attorney for the Southern District. Prosecutors say that Islam kept a database of 50,000 credit card accounts and traded the info over the FBI’s own site, Carder Profit. Islam’s biggest opponent wasn’t necessarily federal agents, though. UFC President Dana White has been after Islam and other hackers since at least January and now he says that he thinks he helped bring down a collective of two dozen computer hackers. The feud between hacktivists and White began earlier this year after the president of the US-based Mixed Martial Arts organization announced his support for the Stop Online Piracy Act, or SOPA, a since-defeated congressional proposal that stood to strike down Internet freedoms across the board. As the public caught on to what the passing of SOPA would do to the Web, online advocates began campaigns to crush the legislation before it could clear Congress. Naturally, White’s outspoken support of the bill brought him some unwanted attention from hacktivists, particularly those with the underground collective UGNazi. Along with hackers aligned to the loose-knight Anonymous organization, the UGNazi clan — and particularly Islam’s alias, JoshTheGod — taunted White over his SOPA support, eventually targeted UFC.com with distributed denial-of-service (DDoS) attacks. As one might expect from the man behind a brutal sport such as MMA, White wasn’t quick to turn quiet. “I’m in the fight biz not the website biz!! Might be a big deal to other companies not mine,” White responded to the cyberattacks at the time over Twitter. Other tweets he sent include statements such as, “Lol, I’m not fucking ebay. My website being down doesn’t mean shit” and “I could give a flying rats ass about UFC. Com.” When White taunted hackers by writing, “The Internet is a place where cowards live,” the response was almost instantaneous: soon after his Social Security number and other personal info was published online. Today, White paints a different picture. Speaking to Inc. magazine, the UFC president suggests that this week’s arrests stemmed from his own snitching to the FBI. “I was in Chicago for a fight when I found out these Anonymous guys had started crashing our site. During an interview, I looked right into the camera and dared them to do it again. I said, ‘Who do you think I am, eBay? I’m in the fight business. I could give a shit if you knock my website down. Do it again! Go ahead. I dare you!’” White tells Inc. “You’re gonna send some pizzas to my house and put my Social Security number out? Who gives a shit? If people really wanted to get your Social Security number, I’m sure they could find it. I’m supposed to bow down to you guys now? I’m going to come after you harder. If you want to fight me, you better pack a f—ing lunch, man. Because we’re gonna go until somebody wins and somebody loses.” White says “It was a Twitter war for days,” but the tides turned after he approached the feds to make things more fun. “You get these guys engaged, you get ‘em going, and that’s when you get the FBI involved,” he says. “Because there’s so much piracy of UFC merchandise, the FBI was already monitoring everything that was happening. But after Anonymous hacked our site, we also got U.S. Immigration and Customs Enforcement, part of the Department of Homeland Security, involved. And it helps when they know when and where the hackers are going to attack. So I put my chin out there, and we knew they were gonna punch it. Two weeks after they attacked me, a lot of them started getting busted. I think we contributed to that.” Islam is being accused of helping operate and administering deals on the FBI-run credit card site and other forums. Last week, the UGNazi clan took credit for an hours-long crash of Twitter.com, a claim the social networking site has since rejected. Source: RT

View article:
UFC.com hit with Distributed Denial of Service ‘DDoS’ attack

LulzSec Members Confess To Distributed Denial of Service ‘DDoS’ Attacks to SOCA, Sony and etc

Four alleged members of the LulzSec hacktivist group had their day in British court Monday. Two of the people charged–Ryan Cleary, 20, and Jake Leslie Davis, 19–appeared at Southwark Crown Court in England to enter guilty pleas against some of the charges against them, including hacking the public-facing websites of the CIA and Britain’s Serious Organized Crime Agency (SOCA). All told, Cleary, who’s from England, pleaded guilty to six of the eight charges lodged against him, including unauthorized access to Pentagon computers controlled by the U.S. Air Force. Meanwhile, Davis–who hails from Scotland’s Shetland Islands–pleaded guilty to two of the four charges made against him. The pair pleaded not guilty to two charges of violating the U.K.’s Serious Crime Act by having posted “unlawfully obtained confidential computer data” to numerous public websites–including LulzSec.com, PasteBin, and the Pirate Bay–to encourage or assist in further offenses, including “supplying articles for use in fraud.” They did, however, confess to launching numerous botnet-driven distributed denial-of-service (DDoS) attacks under the banners of Anonymous, Internet Feds, and LulzSec. According to authorities, the pair targeted websites owned by the Arizona State Police, the Fox Broadcasting Company, News International, Nintendo, and Sony Pictures Entertainment. The pair have also been charged with targeting, amongst other organizations, HBGary, HBGary Federal, the Atlanta chapter of Infragard, Britain’s National Health Service, the Public Broadcasting Service (PBS), and Westboro Baptist church. [ Learn about another hacker indictment. See Feds Bust Hacker For Selling Government Supercomputer Access. ] The two other alleged LulzSec members charged Monday are England-based Ryan Mark Ackroyd, 25, as well as a 17-year-old London student who hasn’t been named by authorities since he’s a minor. Both also appeared at Southwark Crown Court and pleaded not guilty to four charges made against them, including participating in DDoS attacks, as well as “encouraging or assisting an offense.” All four of the LulzSec accused are due to stand trial on the charges leveled against them–for offenses that allegedly took place between February and September 2011–on April 8, 2013. According to news reports, the court heard Monday that reviewing all of the evidence just for the charges facing Cleary will require 3,000 hours. Three of the accused have been released on bail. Cleary was not released; he had been released on conditional bail in June 2011, but violated his bail conditions by attempting to contact the LulzSec leader known as Sabu at Christmastime. LulzSec–at least in its original incarnation–was a small, focused spinoff from Anonymous, which itself sprang from the free-wheeling 4chan image boards. LulzSec was short for Lulz Security, with “lulz” (the plural of LOL or laugh out loud) generally referring to laughs gained at others’ expense. According to U.S. authorities, Davis often operated online using the handles topiary and atopiary, while Ackroyd was known online as lol, lolspoon, as well as a female hacker and botnet aficionado dubbed Kayla. What might be read into Ackroyd allegedly posing as a female hacker? According to Parmy Olson’s recently released book, We Are Anonymous, such behavior isn’t unusual in hacking forums, given the scarcity of actual women involved. “Females were a rare sight on image boards and hacking forums; hence the online catchphrase ‘There are no girls on the Internet,’ and why posing as a girl has been a popular tactic for Internet trolls for years,” wrote Olson. “But this didn’t spell an upper hand for genuine females. If they revealed their sex on an image board … they were often met with misogynistic comments.” In related LulzSec prosecution news, Cleary last week was also indicted by a Los Angeles federal grand jury on charges that overlap with some of the ones filed by British prosecutors. At least so far, however, U.S. prosecutors have signaled that they won’t be seeking Cleary’s extradition, leaving him to face charges in the United Kingdom. The shuttering of LulzSec both in the United States and Great Britain was facilitated by the efforts of SOCA, as well as the FBI, which first arrested Anonymous and LulzSec leader Sabu–real name, Hector Xavier Monsegur–in June 2011, then turned him into a confidential government informant before arresting him again, earlier this year, on a 12-count indictment. As revealed in a leaked conference call earlier this year, British and American authorities were working closely together to time their busts of alleged LulzSec and Anonymous operators on both sides of the Atlantic, apparently using evidence gathered by Monsegur. Source: informationweek

View post:
LulzSec Members Confess To Distributed Denial of Service ‘DDoS’ Attacks to SOCA, Sony and etc

Legalization of Distributed Denial of Service ‘DDDoS’ attacks as a form of protest

Dutch opposition party D66 has proposed the legalization of DDoS attacks as a form of protest. Activists would have to warn of their action in advance, giving websites time to prepare for their attack. ­Kees Verhoeven, the campaign’s leader, argues that it is strange that the fundamental right to demonstrate doesn’t extend to the online realm. The coming years would bring more instances of hacktivism, and it would be reasonable to introduce legislation to regulate, not ban it, he says. Verhoeven proposes that DDoS attacks be legalized so long as the protesters say when they will start their action. That way, a website would have time to prepare for the attack, just like an office building has time to get ready for a rally next to it. The proposal also includes restrictions on transmitting information about a website’s visitors, as well as stricter rules against e-mail spying, and other measures to bolster online privacy. DDoS attacks, popular with hacktivist groups such as Anonymous, would therefore become a legal means to express dissatisfaction with a company or a government. One DDoS attack per year would cost over $10,000 for a financial services company that makes 25 per cent of its sales online, according to Internet traffic management firm NeuStar UltraDNS. If the brand reputation of the company heavily depends on the performance of the website, one DDoS attack a year could end up costing over $20,500. However, DDoS attacks are relatively innocuous compared to other forms of hacking, such as phishing and virus infections, which can cost companies and individuals millions of dollars. Nevertheless, DDoS attacks are so far equated to hacking and are illegal in the Netherlands, as well as many other countries. Source: http://www.rt.com/news/dutch-party-d66-ddos-legalized-protest-541/

Follow this link:
Legalization of Distributed Denial of Service ‘DDDoS’ attacks as a form of protest

Financial Gain is Main Motivation for Cyber Criminals

Announcing the findings of “The Impact of Cybercrime on Businesses” survey, carried out by Ponemon Institute, Check Point Software Technologies revealed that 65% of the organizations which experienced targeted attacks reported that an attacker’s primary objective was to make a financial gain. Disrupting business operations and stealing customer data were attributed as the next likely motivation for attackers, as stated by 45 % of the surveyed organizations. The report also stated that only around 5% of security attacks were driven by political or ideological agendas. The report, which surveyed 2,618 C-level executives and IT security administrators in the US, United Kingdom, Germany, Hong Kong and Brazil across organizations of various types and sizes, showed that companies reported an average of 66 new security attack attempts per week. Respondents in all countries stated that the most serious consequences of such attacks were disruption of business and loss of sensitive information, including intellectual property and trade secrets. Diminished reputation and impact on brand name were the least of their worries, with the exception of respondents in the UK. Successful attacks could end up costing businesses anywhere between $100,000 and $300,000: the participants estimated the average cost of such an attack at $214,000 USD. Tomer Teller, security evangelist and researcher at Check Point Software Technologies, was quoted in the press release as saying, “Cybercriminals are no longer isolated amateurs. They belong to well-structured organizations, often employing highly-skilled hackers to execute targeted attacks, many of whom receive significant amounts of money depending on the region and nature of the attack.” “For the most part, the goal of attackers is to obtain valuable information. These days, credit card data shares space on the shelves of virtual hacking stores with items such as employee records and Facebook or email log-ins, as well as zero-day exploits that can be stolen and sold on the black market ranging anywhere from $10,000 to $500,000,” he added. While Denial of Service (DoS) attacks were seen as the type of cyber crime that posed the greatest risk to organizations, SQL injections were cited, by 43% of the respondents, as the most serious types of attack organizations had experienced in the last two years, the report stated. Other threats cited in the survey included APTs (Advanced Persistent Threats), botnet Infections and DoS attacks cited by 35%, 33%, and 32% of the respondents respectively. On the threats posed by activities of their employees, organizations, across all the surveyed countries, unanimously cited the use of mobile devices such as smartphones and tablet PCs as the biggest concern, followed by the use of social networks and removable media devices such as USB sticks. Hong Kong and Brazil reported on an average the highest percentage of mobile devices infected through an act of cyber crime, at 25 percent and 23 percent, respectively. The U.S. and Germany had the lowest average of infected mobile devices and machines connected to the network at 11 percent and nine percent respectively. The report found that for protecting themselves from these threats, a majority of organizations have instituted Firewall and Intrusion Prevention solutions. However, at the same time, less than half of the surveyed organizations have implemented the necessary protections to fight botnets and APTs. “Cybercrime has become a business. With bot toolkits for hackers selling today for the mere price of $500, it gives people insight into how big the problem has become, and the importance of implementing preemptive protections to safeguard critical assets,” Teller stated. It was pointed out that only 64% of companies said that they have current training and awareness programs in place to prevent targeted attacks. “While the types of threats and level of concern companies have may vary across regions, the good news is that security awareness is rising,” Dr. Larry Ponemon, chairman and founder, Ponemon Institute, was quoted as saying in the press release. “Across the board, C-level executives reported high levels of concern about targeted attacks and planned to implement security precautions, technology and training to mitigate the risk of targeted attacks.” For fast DDoS protection click here . Source: http://www.computerworld.in/news/check-point-survey-financial-gain-main-motivation-cyber-criminals-12922012

See original article:
Financial Gain is Main Motivation for Cyber Criminals

Asia to see rise in cloud DDoS security biz

COMMUNICASIA, SINGAPORE–With the rise of cloud services adoption, businesses also have escalating security concerns over distributed denial of service (DDoS) attacks, and that presents an opportunity for carrier service providers to offer cloud-based DDoS protection, which one industry executive adds is set to gain traction in Asia. Among enterprises, the constant discussion around cloud to make it “sexy and pervasive” to customers cannot ignore the question of what happens when the cloud service becomes unavailable due to an attack, said Lau Kok Khiang, director for Asia-Pacific IP division at Alcatel-Lucent. There is hence “strong pent-up demand” for cloud-based DDoS protection, for which carrier cloud services are in a good position to provide, he said. Lau was presenting at the Telco Rising Cloud conference in CommunicAsia here Tuesday. Large attacks have become commonplace, and enterprises are basically losing the arms race in the Internet security space, Lau described. Among the various DDoS attacks in 2011 alone that saw businesses worldwide suffer a “great amount of damage” involved Sony PlayStation Network, the Hong Kong stock exchange, Visa, MasterCard, PayPal, and WordPress, he pointed out. The executive emphasized that cloud-based DDoS security was a “win-win” scenario for both the service provider and enterprise customers. For the service provider, it is a new revenue opportunity, which also complements existing enterprise services such as virtual private network (VPN) and business broadband. Additionally, this could help drive customer stickiness, Lau said. That is because from the customers’ point of view, having cloud-based DDoS protection ensures 24-by-7 availability of the cloud services they use, which mean better safeguards for their enterprise assets such as confidential client data, he added. On the event sidelines, Lau told ZDNet Asia that cloud DDoS security is set to gain traction in Asia, due to increasing awareness of the risks and prevalence of DDoS. This will prompt companies to consider cloud DDoS protection as added security measures, in order to ensure their service availabilities meet customer demands as well as industry-specific regulations. Also, apart from commercial entities, governments in the region are also pushing the message that organizations need to protect themselves from becoming the next victim of an attack, he added, referring to the massive DDoS attacks that disrupted Internet services in Myanmar in November 2010. Another speaker at the conference, Anisha Travis, partner at law firm Webb Henderson, said while the cloud has benefits and opportunities for businesess, they should go into space with “their eyes open”. In other words, they need to understand and prepare for mitigate the major risks associated with cloud, one of which is service levels, she pointed out during her presentation. It is essential that service level agreements (SLAs) are well-drafted for specific service levels and must also include “practical remedies” when there is downtime or outage, Travis advised. Customers cannot rely solely on the service provider, and should do their due diligence in clarifying ownership, consequences, and failures, she added. Source: http://www.zdnetasia.com/communicasia/asia-to-see-rise-in-cloud-ddos-security-biz-62305165.htm

More here:
Asia to see rise in cloud DDoS security biz

Distributed Denial of Service ‘DDoS’ becoming more ‘sophisticated’, damaging

Distributed denial-of-service (DDoS) have matured with hackers blending different attack techniques and becoming more damaging, observers note. They add that defenses need to evolve to complement infrastructure security that has already been commoditized.” DDoS attacks, where multiple compromised systems usually infected with a Trojan virus, are used to target a single system have been getting more “sophisticated” over the years, Vic Mankotia, security vice president of CA Technologies Asia-Pacific and Japan, noted. Today, there are DDoS attacks coming from automated systems, payloads delivered from USB sticks and protocols such as Bluetooth and magnetic strips of cards, he observed. In the past, DDoS attacks primarily targeted networks using low-level protocol or volumetric attacks, Eric Chan, regional technical director of Fortinet Southeast Asia and Hong Kong, remarked. However, hackers today use a combination of volumetric and application-layer attacking techniques, he noted. An application-layer DDoS targets the application service by using legitimate requests to overload the server, and rather than flood a network with traffic or session, they target specific applications and slowly exhaust resources at the application layer, Chan explained. They can be very “effective” at low traffic rates, which makes them harder to detect, he added. The Sony Playstation breach for example, had been a result of application-layer DDoS attacks, able to camouflage a data breach of over 77 million customer records, he cited. Evolved with IT trends, hackers intent On a basic level, denial-of-service (DoS) has evolved from “taking a pair of wire cutters outside the organization and snipping those wires” 20 years ago, to becoming distributed DoS where “hundreds and thousands of” traffic making computers into botnets to shut down systems, Andrew Valentine, managing principal of investigative response at Verizon observed. Strong connectivity, data centers and cloud, have given mobility center-stage, paved way for the Bring Your Own Device (BYOD) trend making the security parameters “disappear”, Mankotia explained. While mobile devices may not store the target information, but they do allow the DDoS attackers access to the information they seek, he noted. Laptops and devices also have a lot more computing power compared to those in the past, Claudio Scarabello, global security product manager of Verizon added. As such, hardware have a lot more power to flood systems, and can be much more “damaging”, he warned. Another way it has evolved is through the intent, Valentine added. In the past, DDoS had stemmed from “bragging rights”–showing off one’s ability to hack into the server, as well as financial intents, he explained. Today, it is used for political intents, commonly known as hacktivism, and DDoS and data breaches have become “synonymous”, he added, citing the Verizon 2012 data breach investigation report which found a rise in hacktivism against large organizations. “As such, DDoS today is associated with political intent, and making a statement, and not about script kiddies showing off anymore,” he said. Security system with visibility, multi-layered defense needed What is needed is a different type of security to complement the infrastructure security that has already been commoditized–a security system which enables the knowledge of where and who is sharing the data, Mankotia pointed out. DDoS attacks are heavily customized with a signature to get specific information, and security has to evolve as all information is not equal, and all identities, access and system must be in one ecosystem, where content-aware identity and access management are applied and advanced authentication is at its core, he explained. As botnets can send huge amounts of legitimate connections and requests from each compromised machine, and determining whether such connections are valid or not will be crucial, enterprises will need security solutions with “sufficient visibility and context”, Chan added. “These systems should have sufficient visibility and context to detect a wide range of attack types without slowing the flow, and processing of legitimate traffic, and is then able to conduct mitigation in the most effective manner,” he said. Above of, a multi-layer defense strategy is also essential, and the defense strategy must cover both network-layer and application-layer attacks, Chan surmised. In need of protection click here DDoS protection . Source: http://www.zdnetasia.com/ddos-becoming-more-sophisticated-damaging-62305134.htm

Continued here:
Distributed Denial of Service ‘DDoS’ becoming more ‘sophisticated’, damaging

Mascow protest against President Vladimir Putin led to indeptendent Russian websites hit with distributed denial-of-service ‘DDoS’ attack

More than 100,000 protesters on Tuesday joined a march against President Vladimir Putin in central Moscow, organizer and radical left-wing activist Sergei Udaltsov told AFP news agency. “There are more than 100,000 people,” Udaltsov said at the rally, called the March of Millions, which police said had drawn 18,000 people. City authorities allowed up to 50,000 to take part in Tuesday’s event, which coincides with the patriotic Russia Day holiday marking the country’s 1990 declaration of independence from Soviet rule. Moscow police said they were sending 12,000 riot officers and interior ministry troops onto the streets of the capital to keep order. The march will take protesters down Moscow’s Boulevard Ring toward Sakharov Avenue, scene of a dramatic demonstration last December against the outcome of disputed parliamentary elections that month. Meanwhile, independent Russian news websites went offline on Tuesday in a suspected attack by pro-government groups, as protesters gathered in Moscow for a march against President Vladimir Putin’s third Kremlin term. The site of the Moscow Echo radio station went down about a half hour before protesters started to gather on central Pushkin Square. The Dozhd (Rain) TV website and that of the prominent opposition Novaya Gazeta twice-weekly newspaper also could not be accessed as the event officially got under way at 0800 GMT. But the websites of Russia’s main media sources ? including Kremlin-allied papers and state-controlled television stations ? were all accessible and operating without delay. A Dozhd newscaster said their station’s website was the victim of a distributed denial-of-service (DDoS) attack of unknown origin. Opposition leaders have been previously blamed attacks on Russian independent media sources on pro-Putin youth groups. A similar attack, which included the inaccessibility of the same websites during the disputed December parliamentary election, was reported but no one claimed responsibility for that attack, AFP reported. The United States on Monday voiced concern after Russian police raided the homes of top protest leaders ahead of the planned mass rally in Moscow. “The United States is deeply concerned by the apparent harassment of Russian political opposition figures on the eve of the planned demonstrations on June 12,” State Department spokeswoman Victoria Nuland told reporters. Police armed with assault rifles carried out a coordinated sweep of the homes of young Russian politicians, who analysts believe represent the biggest threat to ex-KGB spy Putin’s 12-year rule. Nuland also criticized a new law in Russia that imposes “disproportionate penalties” for violating rules on public demonstrations. Russian police were calling in opposition leaders for questioning one hour prior to the planned rally time on Tuesday in a move “clearly designed to take them off the streets during the demonstration,” she said. “Taken together, these measures raise serious questions about the arbitrary use of law enforcement to stifle free speech and free assembly,” she said. Source: http://english.alarabiya.net/articles/2012/06/12/220172.html

See the original article here:
Mascow protest against President Vladimir Putin led to indeptendent Russian websites hit with distributed denial-of-service ‘DDoS’ attack