Tag: ddos

  • Over 100 Financial Firms Hit by DDoS Attacks

    Over 100 Financial Firms Hit by DDoS Attacks

    More than 100 financial firms were victims of distributed denial-of-service attacks by the same threat actor with North America and Europe overwhelmingly making up the dominant share, according to a recent report.

    Cyber intelligence sharing group FS-ISAC said that over 100 financial services firms were targets of a wave of distributed denial-of-service (DDoS) attacks – a method of overloading a web system with requests in order to prevent it from functioning properly.

    Interestingly, the report claims that the attacks were conducted by the same threat actor within a short period of time.

    The criminals sent extortion notes threatening to disrupt the firms’ websites and digital services, the report said. The threat actor methodically moved across jurisdictions in Europe, North America, Latin America, and Asia Pacific, hitting dozens of institutions within weeks.

    According to the report, North America and Europe made up an overwhelming share of the DDoS attacks with 43 percent and 38 percent, respectively. Asia (15 percent) and Latin America (3 percent) made up less than one-fifth.

    By sub-sectors, retail banking dominated the list, accounting for 41 percent of the DDoS attacks. This is followed by exchange (15 percent), payments (13 percent) and, securities and investment (10 percent).

    In 2021, we have already seen new cyber threats in the form of supply chain attacks, which we can expect to proliferate and evolve quickly, said FS-ISAC’s chairman of the board Jerry Perullo  «The only way to stay ahead of these ever more sophisticated threat actors is to collaborate. Now more than ever, we need global leaders to model what effective sharing looks like to the rest of our community as well as the industry at large.

  • Stop DDoS from ruining your retail Brand’s sales momentum

    Stop DDoS from ruining your retail Brand’s sales momentum

    On 11 November 2017, Alibaba’s Singles’ Day sales hit a new record high with a 39% increase from last year’s sales. The company’s 2017 profits broke world records of Black Friday and Cyber Monday, marking this Asian sales day as one of the highest revenue sales in history.

    With increasing internet-user penetration, consumer behavior is quickly transitioning in Asia today. Shoppers make most of their retail purchases on-the-go, through mobile applications or via websites. In fact, 90% of this year’s Alibaba sales were made through mobile phones.

    Now more than ever, retail businesses in the Asia-Pacific region need to tap onto an omni-channel approach to be aligned with these changing customer demands. Based on the 2016 e-commerce study, Google and Temasek foresee Southeast Asia to be the next region to boom in this market. The predictions indicated that e-commerce will make up 6% of the region’s total retail sales by 2025.

    Beware of business bullies

    While these statistics show a positive growth for the region, businesses going digital must be aware of the lurking threat factors. The physical shoplifters that pained businesses – especially during big sales such as Great Singapore Sale and Black Friday – have now evolved to become cyber criminals. Unlike thieves, businesses are not physically able to discern these criminals, especially since they attack over the network.

    One of the most devastating kinds of cyberattack for e-commerce businesses today is Distributed Denial of Service (DDoS) which aims to bring down websites, therefore, disrupting online services and businesses. DDoS attacks occur when an unusual and unexpected spike in traffic and connection requests overwhelms a website, slows down the network, or in the worst-case scenario, shuts down the entire system.

    A reliable website that guarantees a good user experience is what defines a successful e-commerce business as it is the main platform for acquiring customers and generating revenues. The damage caused by a network failure or a complete site outage will directly and immediately impact business assets. For instance, Alibaba made US$7 billion within the first 30 minutes of the Singles’ Day sale3. Imagine if they had been hit by a DDoS attack; Alibaba would have lost US$233 million per second. Not only would this be a massive loss, the attack would have also caused long term damage to Alibaba’s brand image and customer loyalty. According to KPMG’s annual consumer survey, one fifth of consumers will turn away from a cyber-attacked company4.

    Don’t fall victim

    With the festive period approaching, online retailers can expect an approximately 20% increase in their web traffic5. To make the most out of this sale period, businesses need to ensure that they are ready to protect themselves against DDoS attacks. This includes re-evaluating their network security to assure they are taking the best protective measures.

    Monitor and Detect

    Businesses cannot fight what they do not know. Monitoring network traffic and flow data with DDoS detection alerts security pros to anomalies before they become full-blown catastrophes.

    One way to get a better understanding of what is happening on the network is baselining to know what the traffic looks like during peacetime. This allows organizations to take the appropriate wartime countermeasures when an attack happens. Effective DDoS detection needs to be able to discern the human traffic from the bots.

    Additionally, organizations need a detection solution that can scale given that attacks are increasingly getting larger in size. The best class solution should not only be able to process the data, but also be equipped with the ability to quickly make intelligent decisions with that data.

    Mitigate and Protect

    DDoS protection requires having the right mitigation in place. Businesses should look for a modern DDoS solution that empowers them to automate defenses – from reports to packet captures to mitigation. This can help security pros reduce stress and thwart attacks quickly.

    Communicate

    As with all security procedures, effective DDoS defense involves a human element, as well. It is imperative for businesses to have a communication plan in place in the event of an attack. This includes critical information such as who to notify during, and after an attack. For example, who should be the first to know if the site goes down due to a DDoS attack? Is that the same person notified if a DDoS attack shuts down the online retail site? Who else is notified if an attack happens? Having communications ironed out ahead of time can reduce time to remediation and lower stress levels.

    Make the most of this year’s sale season

    For businesses, these next few months are the time to peak your revenue and customer traffic. It may be a chance to raise brand awareness or even expand the business. Whichever the case, a DDoS attack can be a fatal roadblock to an organization’s goals. Reacting in an efficient manner is key. Online retailers need to ensure they have an emergency response plan that makes good use of anti-DDoS technologies for unforeseeable attacks. For a happy holiday for all, be on the lookout for any dangers and take the right cautionary actions to protect against any potential threats.

     

  • Trojan horse DDoS attacks on the rise

    Trojan horse DDoS attacks on the rise

    The greatest DDoS risk for organisations is the barrage of short, low volume attacks which mask more serious network intrusions,  Corero Network Security has warned.

    According to new Corero research, which highlights DDoS attack attempts against its customers, short, frequent, low-volume DDoS attacks continue to dominate.

    Despite several headline-dominating, high-volume DDoS attacks over the past year, the vast majority (98%) of the DDoS attack attempts against Corero customers during Q1 2017 were less than 10 Gbps per second in volume. In addition, almost three quarters (71%) of the attacks mitigated by Corero lasted 10 minutes or less.

    Due to their small size, these sub-saturating attacks tend to go undetected by IT security staff and many DDoS protection systems. However, they are just disruptive enough to knock a firewall or intrusion prevention system (IPS) offline so that the hackers can target, map and infiltrate a network to install malware and engage data exfiltration activity.

    “Short DDoS attacks might seem harmless, in that they don’t cause extended periods of downtime. But IT teams who choose to ignore them are effectively leaving their doors wide open for malware or ransomware attacks, data theft or other more serious intrusions,”Corero Network Security CEO Ashley Stephenson explained.

    “Just like the mythological Trojan Horse, these attacks deceive security teams by masquerading as a harmless bystander – in this case, a flicker of internet outage – while hiding their more sinister motives.”

    In total, Corero customers experienced an average of 124 DDoS attack attempts per month, equivalent to 4.1 attacks per day during Q1 of 2017. This is a 9% increase in attacks over Q4 2016.

    “Rather than showing their capabilities in full view, through large, volumetric DDoS attacks that cripple a website, using short attacks allows bad actors to test for vulnerabilities within a network and monitor the success of new methods without being detected. Most cloud-based scrubbing solutions will not detect DDoS attacks of less than 10 minutes in duration, so the damage is done before the attack can even be reported,” Stephenson said.

    “As a result, the raft of sub-saturating attacks observed at the beginning of this year could represent a testing phase, as hackers experiment with new techniques before deploying them at an industrial scale.”

    While low volume attacks remain the norm, Corero recorded a significant (55%) increase in large DDoS attacks of more than 10 Gbps per second, in Q1 of 2017, compared to the previous quarter. In addition, while the majority of attacks recorded lasted less than 10 minutes, the data also revealed a slight increase in attacks lasting 20 minutes or longer, with these attacks now accounting for nearly a quarter (22%) of all the attacks recorded.

  • IoT devices drive DDoS attack traffic in Q4

    IoT devices drive DDoS attack traffic in Q4

    Unsecured IoT devices continued to drive significant DDoS attack traffic in the fourth quarter of 2016, according to Akamai’s latest State of the Internet / Security Report.

    The fourth quarter report also revealed that attacks greater than 100 Gbps increased to 12 during the quarter, a 40% year-over-year increase.

    Seven of the 12 Q4 2016 mega attacks, those with traffic greater than 100 Gbps, can be directly attributed to the Mirai IoT botnet.

    But the largest DDoS attack in Q4 2016, which peaked at 517 Gbps, came from Spike, a non-IoT botnet that has been around for more than two years.

    The number of IP addresses involved in DDoS attacks grew significantly this quarter, despite DDoS attack totals dropping overall. The United States sourced the most IP addresses participating in DDoS attacks – more than 180,000.

    “With the predicted exponential proliferation of these devices, threat agents will have an expanding pool of resources to carry out attacks, validating the need for companies to increase their security investments,” said Martin McKeay, senior security advocate and senior editor of the report.

    “Additional emerging system vulnerabilities are expected before devices become more secure.”

    Of the 25 DDoS attack vectors tracked in Q4 2016, the top three were UDP fragment (27%), DNS (21%), and NTP (15%), while overall DDoS attacks decreased by 16 percent.

    Akamai started tracking a new reflection DDoS attack vector this quarter, Connectionless Lightweight Directory Access Protocol (CLDAP), which attackers abuse to amplify DDoS traffic.

    “If anything, our analysis of Q4 2016 proves the old axiom ‘expect the unexpected’ to be true for the world of web security,” continued McKeay.

    “For example, perhaps the attackers in control of Spike felt challenged by Mirai and wanted to be more competitive. If that’s the case, the industry should be prepared to see other botnet operators testing the limits of their attack engines, generating ever larger attacks.”

  • Level 3 opens DDoS scrubbing centers in APAC

    Level 3 opens DDoS scrubbing centers in APAC

    Multinational companies located in the Asia-Pacific region now have access to Distributed Denial of Service (DDoS) mitigation solutions from Level 3 Communications.

    The new scrubbing centers in Hong Kong, Tokyo and Singapore signify an expansion of the company’s security service functionality. The company says its security solutions provide layers of defense through enhanced network routing, rate limiting and filtering that can be paired with cloud-based scrubbing for a more comprehensive mitigation solution.

    The Asia-Pacific region is key for both Asian and multinational enterprises which demand global security services — making Level 3’s cybersecurity solutions and global presence essential.

    Level 3 began operating in Asia Pacific in 2004. The company has 14 on-net markets throughout Asia Pacific with service reach to more than 50 markets in the region. Level 3 offers its customers in the region VPN, direct internet access, Ethernet VPL, managed services, unified communications, CDN and security solutions.

    Level 3 opened the additional scrubbing centers to provide customers with infrastructure in the region to quickly mitigate attacks with less disruption to business operations.

    Level 3’s DDoS ingest capacity, 4.5 terabits per second, provides a high capacity to ingest massive attacks so customers can get back to business as usual.

    The service is carrier agnostic and pulls all customer traffic into Level 3’s globally located scrubbing centers for cleansing before forwarding legitimate traffic through a private connection or the public internet.

    Level 3 now has 11 scrubbing centers on four continents. Other locations include São Paulo, Frankfurt, London, Chicago, Dallas, Los Angeles, New York and Washington, DC.

    24/7 Security Operations Centers detect anomalies in global NetFlow sessions, perform impact analyses, notify customers of threatening conditions and then help them mitigate the issue.

    Australia, China and Hong Kong are listed among the most vulnerable to cyberattacks, according to a report by Project Sonar.

    IoT-compromizing malware research by Level 3 Threat Research Labs reveals many connected devices are being compromised and enabling attacks reaching in excess of 600 Gbps.

  • Rampant growth of DDoS attacks in 2016

    Rampant growth of DDoS attacks in 2016

    The threat of IoT botnets was realized in 2016 and popularized by Mirai, according to a study by Neustar.

    Mirai and similar types of malware compromise IoT device credentials to enrol them into botnets, which are activated by command and control servers.

    As these code assemblies are published, new developments continue to emerge, such as persistent device enrolment, which enables botnet operators to maintain control of a device even after it is rebooted.

    The study also reported that the frequency of DDoS attack mitigations by the company increased 40% in 2016 compared to the same period of time in 2015, according to a study released by the company.

    “With DDoS attacks predicted to become even more complex and ferocious in 2017, increasingly digital organizations within Asia-Pacific will be exposed to more frequent and severe cyber-attacks,” said Robin Schmitt, general manager for APAC at Neustar.

    Multi-vector attacks, which combine attack vectors to confuse defenders and supplement attack volume, also increased 322% and accounted for 52% of the attacks mitigated by Neustar. UDP, TCP and ICMP comprise the three most popular attack vectors, which were leveraged in more than 50% of attacks.

    The report also showed that DNS-based attacks increased 648% with many attackers leveraging DNSSEC amplification to generate massive volumetric pressure.

  • DDoS attacks caused StarHub broadband outages

    DDoS attacks caused StarHub broadband outages

    Singapore’s StarHub has blamed DDoS attacks originating from its customers’ own infected devices for two broadband outages over the past few days.

    At a press conference yesterday, StarHub announced the latest findings of an investigation into the outages on October 22 and 24.

    Both outages lasted for around two hours, leaving many home broadband customers unable to surf the web due to a spike in DNS traffic originating from infected machines.

    Because the traffic originated from StarHub’s own subscribers, it appeared legitimate. But when the attack was detected, StarHub manually filtered out the traffic from the infected devices to restore services for its other customers.

    StarHub announced it plans to send technicians to help customers clean up any infected devices at their homes.

    Singapore’s Cyber Security Agency and the Infocomm Media Development Authority have urged operators to strengthen their defense against DDoS attacks, and noted that this marks the first time Singapore has experienced such and attack on its network infrastructure.

    Darktrace managing director for APAC Sanjay Aurora said operators and ISPs are likely to find themselves increasing targets of attack.

    “The core infrastructure of telecommunications companies is a very desirable target for cybercriminals [but] gaining access is extremely difficult and requires deep expertise in specialist architecture,” he said.

    “What ISPs should be wary of, is the possibility of similar DNS amplification attacks on a more regular basis, given that they require relatively little skill and effort but can cause a large amount of damage. This makes them increasingly popular among hackers.”

    He said DNS-based DDoS attacks can impact networks by saturating bandwidth with malicious traffic, while also increasing volumes of support calls and negatively impacting  the customer experience and ultimately revenue.

    Aurora added that there is a possibility that the DDoS attack was caused by Mirai, the IoT botnet responsible for the recent DDoS attack against US-based DNS service provider Dyn. This attack used infected IoT devices.

  • Singtel expands MSS alliance with Akamai

    Singtel expands MSS alliance with Akamai

    Singtel announced it has expended its alliance with Akamai by becoming the world’s first telco provider to have its advanced security operations centre staff certified to deliver Akamai managed security services.

    The two companies teamed up last month to offer DDoS mitigation services based on Akamai’s Intelligent Platform to enterprises across APAC.

    Now this alliance has been expanded, with Singtel’s ASOC staff trained and certified to deliver professional managed and security services for Akamai’s web security portfolio in the region.

    Singtel is launching the capability for Singapore enterprises first before expanding it to other regional APAC markets.

    “This partnership augments our award-winning Managed Security Services by integrating our ASOC in Singapore with Akamai’s best-in-class cyber security solutions,” Singtel Group Enterprise managing director for cyber security William Woo said.

    “The partnership further strengthens our existing relationship with Akamai, taking it to a new level of collaboration to reinforce Singapore as a safe business hub, and the Asia Pacific as a region which is conducive for doing business.”

    Singtel operates a network of eight security operations centers across Asia, Europe and the US, including its advanced security operations center in Singapore.