Tag Archives: development

DDoS as dance: Anonymous hits the ballet

A new multimedia ballet, “HackPolitik,” fuses jarring, angular movements with electroacoustic music and video projection to interpret the activities of hacker collective Anonymous. Hacker collective Anonymous is going to the ballet. Take that in; it’s not often you’ll see Anonymous and ballet in the same sentence. The unusual pairing will take place November 15 and 16 at the Boston University Dance Theater, where the Juventas New Music Ensemble debuts “HackPolitik,” a new contemporary ballet based on the hacktivist group’s activities and personalities. The piece combines electroacoustic music, modern dance, and video projection to examine how the Internet impacts 21st century discourse and sometimes blurs the lines between activism and anarchy. Instead of pastel tutus, expect to see dancers in black and white, with dramatic face paint that evokes Guy Fawkes masks. And erratic, sometimes militant movements instead of fluid pirouettes. How do hacks on Twitter and LinkedIn accounts translate to physical movement? Neither the dance nor the music is neatly representative of things like Web site defacements, distributed denial-of-service attacks, and data theft, though they do aim to capture the mood of cyber insurgency. One scene, for example, opens with a soloist appearing to search for a way into something. Once she’s successful, the rest of the dancers join her with a series of advancing movements directed at one point in space that’s meant to represent the entity being attacked. “The movement interprets the initial culture of Anonymous as a crass, chaotic, and immature world out of which particular personalities and goals emerge,” choreographer Kate Ladenheim tells CNET. “For example, in the opening of the piece, we created a phrase that we lovingly refer to as the ‘f*@% you’ phrase. There are 10 examples of immature gestures/f*@%-you hand motions that are abstracted to become full bodied and then traveled through space in various ways.” This was Ladenheim’s take on trolling, memes, and the “all-around chaos of IRC and online message boards like 4chan.” The idea for “HackPolitik” came to Boston-based composer Peter Van Zandt Lane in late 2011, when some of Anonymous’ more high-profile politically driven cyberattacks grabbed the spotlight. Lane teaches a course at Brandeis University called “Protest and Propaganda in Music,” but hadn’t had much occasion to meld those interests with his creative work. “The idea of a ballet based on the global hacktivist movement excited me, as it was a way I could potentially pull these three spheres together,” he tells CNET. The two-act piece touches, among other things, on the December 2010 distributed denial-of-service attack on PayPal. It was organized in response to PayPal halting donations to the online leaked-documents clearinghouse WikiLeaks. Another of the ballet’s 10 scenes references Anonymous’ 2011 attack on HBGary Federal, a security firm trying to investigate the loosely organized global group. “The music, on its own, says…disorder, absurdity, cohesion/collaboration, militaristic triumph, humiliation, betrayal, etc.,” Lane says. “Choreography can connect these expressions a bit more concretely to the activities of Anonymous, but ultimately, the audience has to make connections themselves, between a generally abstract art form and the specific events that inspired them.” To create the ballet, Lane; Ladenheim, artistic director of NY-based contemporary dance company The People Movers; and conductor Lidiya Yankovskaya, artistic director of the Juventas New Music Ensemble, mined author Parmy Olson’s writings on Anonymous, which closely examine the global activist movement. Anonymous has supporters worldwide, as evidenced by this week’s “Million Mask March” in cities from Washington, D.C., to Tokyo to Sao Paulo, Brazil. Some pioneers of the hacktivist movement, however, have criticized Anonymous, saying its methods abridge free speech and hurt the cause . But “HackPolitik,” Lane insists, isn’t about taking sides. “For me,” he says, “the piece is less about answers, and more about bringing up questions on how we emotionally and artistically are able to respond to the influence of technology on our society.” Source: http://news.cnet.com/8301-17938_105-57611236-1/ddos-as-dance-anonymous-hits-the-ballet/

Taken from:
DDoS as dance: Anonymous hits the ballet

Denial of Service (DDoS) Cyber attacks – are they using the same logic as terror threats?

Much has been discussed about the damage that the Advanced Persistent Threat (APT) attacks cause to corporates and governments alike. It is estimate that at least 50% of Fortune 500 companies have been compromised by APT, and the potential financial damage to these organizations is almost impossible to quantify, but probably in the trillions of US dollars. Compared to this a crude Denial of Service (DoS) attack or its more advance siblings, the Distributed Denial of Service (DDoS) attacks and Distributed Reflector (DRDoS) attacks, their outcome seems pretty benign- your site is being bombarded by thousands of request for information, until the server gives up and no-one can actually use the site. Once the attack stops, access is possible again and no damage to your IT infrastructure has occurred, no data or money was stolen and hopefully your angry customer will believe it was just a “site malfunction”. But as attack methods have become more sophisticated AND more accessible (for example, now one can simply rent hundreds of BOT computer as a service, to carry the attack for him, using a simple interface, with no need to know how to actually hack), the industry had to act, and developed means to mitigate these attacks. Several methods of DDoS mitigation exist and multiple companies offer these as a service. Now a very dangerous equation begins to unfold, one where the attacker can use simple, cheap tools (a fairly typical rate for DDoS botnet rental hovers around the $200 for 10,000 bot agents per day), and the defender must invest much larger resources, both internal (maintaining a Security Operations Center or SOC) and external (service providers), creating an inherent asymmetry. This asymmetry means that organizations wishing to mitigate this threat will keep investing (or throwing, since there is no actual gain here, only minimizing the impact) money over time, until they are in serious economic pain. And this is exactly what Islamic terrorist have been trying to do in the recent global jihad campaign- making western countries bleed money in order to try and prevent sparse attacks carried by rudimentary means. As Osama bin Laden said: “It is very important to concentrate on hitting the American economy with every available tool … the economy is the base of its military power. The United States is a great economy but at the same time it is fragile.” The risk is that using offensive cyber means one can achieve this goal much faster (and one does not have to blow himself to pieces in the process, or hurt innocent people). Therefore, prevention and not only mitigation is necessary. Organizations must be far more proactive than they are now. Sure, investments in IT security and best practices are always a good idea, but also applying preventive intelligence to greatly reduce the impact of attacks. This, couples with harsher legislation and enforcement against both the suppliers and the perpetrators of the attacks will hopefully, in the end, balance this asymmetric equation. For protection against your eCommerce site click here . Source: http://defense-update.com/20131107_denial-service-ddos-cyber-attacks-using-logic-terror-threats.html

Read the original:
Denial of Service (DDoS) Cyber attacks – are they using the same logic as terror threats?

Avoiding Website Outages During the Holiday Season

The holiday shopping season is practically upon us, and online retailers don’t want to endure any IT downtime between Thanksgiving and Christmas when many ring up a third of their annual receipts. That’s a lot of green. Online shopping carts should register nearly $100 billion this holiday season in online sales – up 12% from a year ago, estimates Shop.org. What can online retailers do to avoid outages and other disruptions? It’s an important issue because an estimated one-in-five retailers suffered outages last year. The damage? Forty-five% estimated they could lose $500,000 to $5 million in one day due to a website crash. Gartner consultants predict a 10% growth in the financial impact that cybercrime will have on online businesses through 2016. They see distributed denial-of-service (DDoS) attackers taking advantage of new software vulnerabilities to begin an assault with multiple sources and often multiple targets. These can be introduced via employee-owned devices used in the workplace and even via the Cloud. Actions to Take Now While it’s probably too late to take major actions this holiday season, retailers can still take some steps to minimize such disruptions. However, to really combat the outage and downtime challenges, retailers should begin taking more effective steps after the New Year starts to get ready for the 2014 holiday rush. Three-of-four online retailers (77%) strengthened their online IT defenses this year to reduce downtime from last year. Downtime certainly occurs. Considering the common 99.5% system uptime, this leaves 43 hours – roughly one-and-a-half days – of downtime yearly.  A key focus area should be ensuring your site can handle rapid and unexpected increases in demand. That demand can take two forms: desired demand, which should be scaled up Cyber Monday and undesired demand, which should be mitigated, like a cyberattack. Here’s what online retailers still can do before the approaching Big Season. Determine whether you can handle the increased traffic from desired demand expected during the holiday season, especially on Cyber Monday, when online sales soar. You might still be able to turn to cloud-based services to add capacity and prevent a site crash. But if you don’t have a cloud provider, it’s probably too late to make those arrangements and transfer your data to the provider’s site. Determine if you have adequate mitigation capabilities for DDoS attacks from hackers. The last quarter of the year, primarily holiday season, is when DDoS attacks increase in size and intensity. In the 2012 fourth quarter, one DDoS protection service mitigated attacks that reached more than 50 gigabits per second directed against ecommerce clients; the average attack duration was 32.2 hours. Find out how various types of DDoS threats can impact different elements of your network and determine mitigation actions that can protect them, including employing a DDoS mitigation service. Keep tabs on blogs and social media sites because hackers enjoy bragging about their activities and sometimes disclose their next industry target. Make sure your payment data being collected remains secure because attackers often are going after customer credit card data. For retailers about to begin or who have begun what’s called the “network freeze,” in which no changes of any type can be made to their network and system components or apps operations until mid-January to avoid triggering downtime, if any severe vulnerability that has the potential to cause downtime is found, an emergency change window should be requested to remediate the problem – even during the “freeze.” This “freeze” practice actually is a Payment Card Industry (PCI) regulation. But only 21%bof businesses that store credit and debit card data comply with that regulation in between their mandatory annual audits, a Verizon study finds. What to Do for Next Holiday Season When the holiday and post-holiday sales rush slows, begin thinking about the 2014 holiday season, especially if you’re really bent on enhancing your defenses and scalability against downtime or outages and you haven’t taken major steps yet. Here are some suggested initiatives: Confer with a consulting firm or a data center or cloud provider about what you need to do, specifically, to realize your objectives. Consider actually retaining a service provider that delivers services to help you scale out and protect your IT operations. Going to the cloud doesn’t alleviate your IT responsibility where security is involved. The cloud doesn’t necessarily make your apps secure. A service provider can work with developers to develop and meet these objectives. Shift to a scale-out IT model so your applications scale out, not up, and this may require application transformation efforts to make you application resilient even when infrastructure services are disrupted in local regions. Act early in the year because this type of transformation effort will require changes across all parts of your infrastructure and application; no real shortcut exists and there won’t be time to make these types of changes once the selling season is upon you. Embrace cloud-type platforms if you’re a seasonal online retailer because they’re more dynamic and it’s easy to scale up quickly to meet demand and not incur extra costs when the demand isn’t there. Look into establishing a hybrid cloud so those apps that can’t be moved to the cloud quite yet, can continue to be handled in their traditional manner. For instance, you might use the cloud for web and application tiers and keep other operations in your normal IT setup until you are ready to take on the transformation actives required to update your database environment. Be sure to test your enhanced system before the holiday season and design it to support 100% availability because your goal must strive to always be up. This means securing secondary and tertiary facilities and resources far apart from your principal facility so if an outage occurs in one site, the load can be automatically shifted to an alternate site. Lastly, understand your key performance indicators, or KPIs – those measurements used to evaluate the success of particular activities in which you’re engaged. To do this well, you must possess a firm understanding of the KPIs across all tiers of your applications. Certainly for online retailers, the holiday selling season is critical to their financial strength and even survival. That’s why it’s imperative to keep your IT operations up and running and to recognize and repel cyber-attackers. But remember. You can’t do everything.  Simply do what you can for this year and move swiftly to prepare for the 2014 holiday season. Source: http://multichannelmerchant.com/crosschannel/avoiding-outages-holiday-season-06112013/

Read More:
Avoiding Website Outages During the Holiday Season

Jurassic DDoS?

Like something from the digital ice age, distributed denial-of-service (DDoS) attacks have thawed and are roaming the cyber planet again, according to data from Google in collaboration with Arbor Networks, which provides insight into the scale and geography of recent cyber strikes. Various other reports support the same theory. Verisign estimates that a third of downtime incidents stem from DDoS attacks. These attacks are costly for both businesses and consumers, and the costs are rising. The security firm Prolexic found that attacks became bigger and more frequent in 2013 vs. 2012. There was a 58% increase in total DDoS attacks; 101% increase in application layer (Layer 7) attacks; 48% increase in infrastructure (Layer 3 &4); and 12.4% increase in average attack duration. In addition to an increase in frequency and scale, Prolexic observed some interesting metrics that illustrate significant changes in DDoS attack methodologies. Most notably was a shift away from the bulky flat packet SYN floods to UDP-based attacks and the rapid adoption of Distributed Reflection Denial-of-Service (DrDoS) attacks. A “reflection attack” is a compromise of a server’s security caused by tricking it into giving up an authentication security code, allowing a hacker to access it. These attacks are made possible when servers use a simple protocol to authenticate visitors. It exploits a common security technique known as a challenge-response authentication, which relies on the exchange of secure information between authorized user and server. The hacker logs on and receives a challenge. The server is expecting an answer in the form of the correct response but instead, the hacker creates another connection and sends the challenge back to the server. In a weak protocol, the server will send back the answer, allowing the hacker to send the answer back along the original connection to access the server. Systems that use a challenge-response authentication approach to security can be vulnerable to reflection attacks unless they are modified to address the most common security holes. Reflection attacks use a different kind of bot and require a different type of server to spoof the target IP. Prolexic believes the adoption of DrDoS attacks is likely to continue, as fewer bots are required to generate a high volume of attack traffic due to reflection and amplification techniques. Such attacks also provide anonymity by spoofing IP addresses. Another interesting observation by Prolexic is that infrastructure-based attack protocols such as SYN floods remain in steady use and are often implemented in conjunction with the reflection attacks. The US and China are popular targets simply because these two countries have more internet users than any other country, and both countries are popular choices for ideologically based attacks. The top ten DDoS originating countries according to the Prolexic Quarterly Global DDoS Attack Report Q3 2013 are: China – 62% United States – 9.06% Republic of Korea – 7.09% Brazil – 4.46% Russia – 4.45% India – 3.45% Taiwan – 2.95% Poland – 2.23% Japan – 2.11% Italy – 1.94% So, what does the future hold for DDoS attacks? Future DDoS attacks will likely be conducted through the use of booter scripts, stressor services, and related Application Programming Interfaces (API). The increasing use of this attack method will result in much more effective attacks with fewer resources required. Since these attacks are easier to employ, DrDoS attacks will become more popular. In fact, according to Prolexic, script kiddies are graduating into digital crime and assembling DDoS-for-hire sites for as little as five dollars ($5). That $5 can buy you 600 seconds of DDoS and just $50 could put a credit union down for an afternoon. Remember, it costs far less to generate an attack than to mitigate an attack. Security professionals must promote cleanup efforts and make it difficult for hackers to send money to criminals offering DDoS for hire. The financial institutions with smaller security budgets become more lucrative targets because they cannot apply the resources to identify threats. Verizon’s Chris Novak agreed: “We are seeing where DDoS is used to distract a medium-size financial institution. While they are busy fighting off the DDoS, they don’t see that terabytes of data just walked out the door. That’s scary.” DDoS is not dead. In fact, it is alive and kicking. In addition to the foray of targets, many new government programs have become recent hacker targets using DDoS. As new software is developed, it is incumbent on IT security professionals to be cognizant of potential DDoS vulnerabilities and to initiate countermeasures as quickly as possible. Source: http://www.infosecurity-magazine.com/blog/2013/11/5/jurassic-ddos/1050.aspx

Read the original:
Jurassic DDoS?

Anonymous Philippines hack and DDoS Government sites

Critics of the Aquino administration responsible for hacking government websites will be dealt with accordingly, Malacañang warned yesterday. “There are existing laws against hacking and proper action will be taken,” Press Secretary Herminio Coloma told a news briefing when sought for comment on the latest attacks on the websites of several government agencies by activist hacker group Anonymous Philippines. “There are sufficient avenues for free expression so there is no need to resort to illegal acts such as hacking of government websites,” Coloma said. He said that sentiments against the government could be aired in street protests. According to Coloma, there is enough “democratic space” where the public can air their grievances. More gov’t sites under attack Anonymous Philippines claimed it has stopped the operation of major government websites as hackers geared up for today’s “Million Mask March” in Quezon City. In a post on its Facebook page yesterday, the group said the websites of around 100 local and national government agencies – including that of the Official Gazette, Senate, House of Representatives and the National Bureau of Investigation – were “currently down.” With the exception of the Senate website (senate.gov.ph), a random check showed that most of the national government websites in the list were accessible as of yesterday afternoon. Despite having a security feature to mitigate attacks, the Official Gazette website (gov.ph) was temporarily inaccessible yesterday. In a phone interview with The STAR, Roy Espiritu of the Information and Communications Technology Office confirmed that a number of government sites have been under distributed denial of service (DDoS) attacks since Monday. However, he said that “critical” government websites are “secure.” Espiritu said government websites are currently in the process of migrating into more secure servers as mandated by Administrative Order 39, signed by the President in July, which establishes a Government Web Hosting Service. The service seeks to “ensure the government’s Internet presence around the clock under all foreseeable conditions.” Earlier, Espiritu said they are looking into the possibility of incorporating security measures to beef up the defenses of government websites. A DDoS attack is mounted to shut down an Internet site by flooding it with access requests and overload its server handling capabilities. Websites affected by successful DDoS attacks are inaccessible to legitimate users who wish to view their content. The Official Gazette website is protected from DDoS attacks by CloudFare, which offers security by checking the integrity of browsers and looking for threat signatures from users who wish to access the site. DDoS attacks are dependent on the number of people trying to access the website at the same time. Espiritu earlier said that even the most secure websites could be affected by such attacks. In 2010, the websites of Visa and MasterCard were affected by a DDoS attack mounted by supporters of whistle-blower organization WikiLeaks. DDoS attacks are different from hacking, which requires an Internet user to access the website using the password of a legitimate administrator. Investigation According to Espiritu, an investigation will be conducted to determine the people behind the attacks on government websites. He said the people behind the attacks may be charged under the e-Commerce law as the move to shut down the websites deprived the public of the information that they need from the government. On Monday, the website of the Office of the Ombudsman was defaced by people claiming to be members of Anonymous Philippines. The latest cyber attacks on government websites came amid issues involving alleged misuse of the Priority Development Assistance Fund and the Disbursement Acceleration Program of the legislative and the executive, respectively. In August, various government sites were hacked during the Million People March attended by thousands in Luneta. Previous incidents of attacks happened during the height of discussions on various issues such as the passage of the Cybercrime Prevention Law and the territorial dispute with China. Worldwide protest The Million Mask March is an event that will be held in various locations around the globe today “to remind this world what it has forgotten. That fairness, justice, and freedom are more than just words.” According to its official Facebook page, the march will cover various topics including government, education reform, constitutional rights, freedom, unity, drug abuse, respect for all, corruption, nutrition and health and violence among children, among others. Based on the events page of the Million Mask March-Philippines, over 1,000 Facebook users have confirmed attendance in today’s march. A post by an Anonymous member said participants will meet at the Quezon Memorial Circle at 8 a.m. to discuss the activities for the day. The march will start in front of the Sandiganbayan along Commonwealth Avenue to Batasang Pambansa. In a text message to The STAR, Quezon City department of public order and safety chief Elmo San Diego said they received no application for a permit to hold a rally or a march near Batasang Pambansa today. The Anonymous member reminded participants not to bring any form of weapon, adding that the event will be held to show the public’s reaction to the mishandling of the government committed by people in power. The Department of Science and Technology (DOST) Information and Communications Technology Office yesterday underscored the need to fast track efforts to set up a more secure government website hosting facility following the latest hacking of government websites. The websites of the Insurance Commission, Southern Philippines Development Authority, Optical Media Board and that of the local government units of Bolinao, Pasig City, Pateros and the municipality of Basnud, Oriental Mindoro were defaced by members of Anonymous Philippines. Source: http://www.philstar.com/headlines/2013/11/05/1253167/palace-act-vs-hackers

Read More:
Anonymous Philippines hack and DDoS Government sites

Extra Life DDoS Attack: Children’s Charity Extra Life Website Hit By DDoS During Annual Gaming Marathon

Extra Life — a charity organization dedicated helping Children’s Miracle Network Hospitals through an annual gaming marathon — has been hit with a Distributed Denial of Service (DDoS) attack. According to Escapist Magazine, Extra Life raises money for Children’s Miracle Network Hospitals by taking pledges and then playing games — anything from video games to board games and tabletop miniatures — for 25 hours straight. Extra Life was in the middle of this year’s event, which began at 8 a.m. today and ends at 8 a.m. on November 3, when their website suddenly went down. As a result, pledges could not be taken. News of the DDoS attack was confirmed with a statement on the Extra Life Facebook page by founder Jeromy “Doc” Adams: “We’ve discovered that the Extra Life website experienced a DDoS attack against our datacenter,” the statement reads. “I am not sure what kind of person would DDoS a charitable initiative. I am so sorry that you are going through this frustration today. Our entire team is purely heartbroken that someone would do this. But it has happened. As frustrating as this is for everyone involved, it pales in comparison to what the kids we’re trying to save go through. That reality, for me personally, is about the only thing keeping me somewhat calm right now. “I am very angry and very sorry,” the statement continues. “You deserve better than this. The kids deserve better than this. Extra Life has given a lot of us some of the happiest moments in our lives. This is not one of those moments. Please hang with us through this. It is important that we spread the word. Please get on every form of social media you can and tell your friends what happened. We can overcome this together.” After a few of hours of downtime, the Extra Life website was back online.   Many took to Facebook to vent their outrage that hackers would choose to DDoS a charity organization. “I understand DDoS’ing a website of a corrupt business or government, but…Why would someone DDoS this?” one user wrote. “May whoever did this lose their shoes and have every child in their neighborhood strew Legos in their path forever,” another user commented. A DDoS attack takes place when hackers use an army of infected computers to send traffic to a server, causing a shutdown in the process. Source: http://www.ibtimes.com/extra-life-ddos-attack-childrens-charity-extra-life-website-hit-ddos-during-annual-gaming-marathon

Originally posted here:
Extra Life DDoS Attack: Children’s Charity Extra Life Website Hit By DDoS During Annual Gaming Marathon

OpThrowback: Anonymous to Launch DDOS Attacks Against FBI, NSA.

  Anonymous hackers, more precisely the ones who hacked a couple of Syrian government websites last week, have announced the start of a new campaign called Operation Throwback. ~ SoftPedia The goal of the operation is “to strike back against the oppressors of our freedom.” The hackers say they will launch distributed denial-of-service (DDOS) attacks against several high-profile websites. Today, on October 28, they plan on launching a cyberattack against the main website of T-Mobile. On October 31, they plan on attacking the website of the FBI, the NSA, Verizon, Microsoft and AT&T. The hacktivists urge their supporters to download DDOS tools and VPNs. The initiators of the operation are providing download links and instructions on how to use them. Earlier today, the hackers tested their “firepower” against the official website of the American Nazi Party. At the time of publishing NCB Interpol web site was down, apparantly from Ddos attack. Source: http://revolution-news.com/opthrowback-anonymous-to-launch-ddos-attacks-against-fbi-nsa/

View original post here:
OpThrowback: Anonymous to Launch DDOS Attacks Against FBI, NSA.

12 year old Quebec boy Anonymous Hacker Pleads Guilty to DDOS Attack on Government Websites

A 12-year-old Quebec boy is responsible for hacking several government and police websites during the student uprising in spring 2012, creating computer havoc and causing $60,000 damage, court heard Thursday. Some sites were out of service for up to two days and the boy did it in the name of the activist/hacktivist group Anonymous. The Grade 5 student from the Montreal suburb of Notre-Dame- de-Grâce, whose actions were not politically motivated, traded pirated information to Anonymous for video games, court was told. The boy appeared in youth court Thursday dressed in his school uniform and accompanied by his father. He pleaded guilty to three charges related to the hacking of the websites, including those of Montreal police, the Quebec Institute of Public Health, Chilean government and some non-public sites. Police estimate damage to the sites at $60,000 but a more detailed report will be produced in court when the boy is sentenced next month. The little hacker, whose name can’t be published and is said to have been involved with computers since the age of nine, contributed to the crash of some sites and accessed information belonging to users and administrators. He had even issued a warning to others: “It’s easy to hack but do not go there too much, they will track you down.” Court heard the boy used three different computer attacks, one which resulted in a denial of service to those trying to access the websites and flooded servers, making them ineffective. In another method he would alter information and make it appear as the homepage. His third tactic involved exploiting security holes in order to access database servers. “And he told others how to do it,” a police expert testified in Montreal on Thursday. While others were arrested in the scheme, it was the boy who opened the door to the website attacks, court heard. “He saw it as a challenge, he was only 12 years old,” his lawyer said. “There was no political purpose.” In 2000, a 15-year-old Montreal boy, know as Mafiaboy, did an estimated $1.7 billion in damage through hacking. He was sentenced to eight months in youth detention and subsequently received several job offers in cybersecurity. Source: http://www.torontosun.com/2013/10/25/que-boy-12-pleads-guilty-to-hacking-government-websites

Read More:
12 year old Quebec boy Anonymous Hacker Pleads Guilty to DDOS Attack on Government Websites

NSA site down due to alleged DDoS attack

The website for the United States National Security Agency suddenly went offline Friday. NSA.gov has been unavailable globally as of late Friday afternoon, and Twitter accounts belonging to people loosely affiliated with the Anonymous hacktivism movement have suggested they are responsible. Twitter users @AnonymousOwn3r and @TruthIzSexy both were quick to comment on the matter, and implied that a distributed denial-of-service attack, or DDoS, may have been waged as an act of protest against the NSA   Allegations that those users participated in the DDoS — a method of over-loading a website with too much traffic — are currently unverified, and @AnonymousOwn3r has previously taken credit for downing websites in a similar fashion, although those claims have been largely contested. The crippling of NSA.gov comes amid a series of damning national security documents that have been disclosed without authorization by former intelligence contractor Edward Snowden. The revelations in the leaked documents have impassioned people around the globe outraged by evidence of widespread surveillance operated by the NSA, and a massive “Stop Watching Us” rally is scheduled for Saturday in Washington, DC. DDoS attacks are illegal in the United States under the Computer Fraud and Abuse Act, or CFAA, and two cases are currently underway in California and Virginia in which federal judges are weighing in on instances in which members of Anonymous allegedly used the technique to take down an array of sites during anti-copyright campaigns waged by the group in 2010 and 2011. In those cases, so-called hacktivsits are reported to have conspired together to send immense loads of traffic to targeted websites, rendering them inaccessible due to the overload.

More:
NSA site down due to alleged DDoS attack

A DDoS Attack Could Cost $1 Million Before Mitigation Even Starts

A new report suggests that companies are unaware of the extent of the DDoS threat, unaware of the potential cost of an attack, and over-reliant on traditional and inadequate in-house defenses. Marking its inaugural International DDoS Awareness Day, Neustar has released new research into business awareness of contemporary denial-of-service attacks. IDG Research Services questioned more than 200 IT managers for companies with an online marketing or commercial web presence; 70% of which were involved in e-commerce operations. The study finds that it takes an average of ten hours before a company can even begin to resolve a DDoS attack. On average, a DDoS attack isn’t detected until 4.5 hours after its commencement; and a further 4.9 hours passes before mitigation can commence. With outage costs averaging $100,000 per hour, it means that a DDoS attack can cost an internet-reliant company $1 million before the company even starts to mitigate the attack. With the year’s peak shopping period fast approaching, it is something that cannot be ignored. “If an attack results in an outage lasting days, the economic results could be catastrophic. To some companies, it could even be fatal,” warns Neustar. One problem, suggests Susan Warner, Neustar’s market manager for DDoS solutions, is that IT administrators may not be fully aware of the business implications of downtime. “For example,” she says, “an administrator may believe that if the system goes down for a few hours it’s not a big deal, but may not realize there is going to be hundreds of thousand of dollars of marketing spend lost for every hour of site downtime.” A second problem is either a misunderstanding of the nature of modern attacks, or a basic belief that DDoS attacks will always go after someone else. Most companies rely on in-house technology to defend against attacks: 77% have firewalls, 65% have routers and switches, and 59% have intrusion detection. But only 26% use cloud-based mitigation services. Nevertheless, there is a strong belief among these IT managers that they are adequately protected: 86% of the respondents are either somewhat, very or extremely confident in their defenses. But new DDoS techniques such as DNS amplification/reflection, warns Neustar, “can easily overwhelm on-premise defenses and even congest the presumably vaster resources of an ISP.” In fact, in the face of a major attack, in-house defenses can make matters worse. A lot of enterprises, warns Warner, “believe they have some technology already in place that will help them, such as a firewall or a router that can handle some extra traffic, but a high-volume DDoS attack is going to quickly overwhelm those traditional types of defenses and they will rapidly become part of the bottleneck.” “Responding to this new reality,” says the report, “requires actionable continuous monitoring and analysis against realtime threat intelligence, and constantly evolving incident management scenarios.” The answer lies in the cloud. “Cloud-based mitigation is achieved either by redirecting your traffic during an assault or having it always go through a cloud service,” says Warner. “An always-on type of approach can also be achieved through a hybrid solution that provides mitigation resources on-site; if they begin to be overwhelmed, a failover to a cloud service is immediately activated.” Source: http://www.infosecurity-magazine.com/view/35238/a-ddos-attack-could-cost-1-million-before-mitigation-even-starts

View article:
A DDoS Attack Could Cost $1 Million Before Mitigation Even Starts