Police to hold major exercise in central London th... » A major exercise to test the emergency services and Government response to a terrorist attack will b... Most major financial hacks completely covered u... » London, UK: Despite devastating cyber attacks being reported daily in the media, a new survey from L... What Makes Close Protection Unique? » TB Close Protection Operatives have to deal with a wide range of threats that many others who uti... AN APPEAL FOR THE INAUGURATION OF THE NATIONAL W... » A Diaspora Note to PDP, Other Political Parties, Civil Liberties Organisations, Churches, Mosques, N... World of tanks and Google invite you into a virtua... » World of Tanks and Google Invite You into a Virtual World! Imagine feeling the turret shake on a Cen... Blaxtair restrategise its relations with diverse ... » Over 5 years, the basic model has continuously evolved and many clients have chosen this solution to... Clavister patrners with major telecom firms to ... » Clavister has partnered with DataCom and Ruckus Wireless to build a large, secure and reliable WiFi ... AdaptiveMobile set to protect one fifth of worl... » DUBLIN & DALLAS: AdaptiveMobile has expanded to protect one fifth of the world’s mobile subscribers ... PILGRIMS TAKES ITS PLACE IN TOP 5% OF SECURITY COM... » LONDON: Security specialist Pilgrims Group Limited has officially been ranked in the top 5% of all t... PALFINGER establishes a joint venture for the Amer... » - FairWind Renewable Energy Services, LLC will service American wind energy plants - PALFINGER w...

CLICK HERE TO

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

Lessons learnt from SpamHaus DDoS attack

Vigilance can report that last week, as part of the Spammer-Anti-Spammer wars, an attack on Spamhaus was created using a DNS amplification attack on highly rated DNS servers, the attack used Botnets to send an initial reflection request to the DNS Servers, which then generated the actual traffic. Today, although we are not sure if the same vector of attack was used again, the attack was able to draw enough web traffic to Spamhaus to reach a reported peak of 300Gbps of DDoS – a respectable number indeed. It is clear that proper DNS Server monitoring and configuration should have deflected the attack at an early stage. The DNS Attack vector showed again the effectiveness of using servers as initial attack vectors rather than a user-based botnet.

 

Spamhaus cyber attack

In his reaction to the news around the Spamhaus cyberattack, which researchers are describing as the world’s largest ever cyber attack and is slowing down global internet services, Tim Keanini, CRO at nCircle, said: “While this is making the news, this is the day in the life of a service provider as these attacks are common place. Yes, this one is larger but again that is a product of more and more computers get compromised to become a part of these botnets and these computers are being connected at higher and higher speeds each year.”

Mr Keanini added:“Application amplification is also something that has been around for quite some time. Anytime you have a situation where 1 packets can be spoofed and sent to a destination that will return 2 or more packets (returning 5 gets you a 5:1 amplifier), you can be damn sure that DDoS’er will know how to leverage it. This also stresses the importance of monitory ingress/egress filtering at the border routers to make it impossible to spoof addresses. My point is that all the counter measures for this type of attack once it has begun will be at the service provider level so get to know your service provider and understand their practices when it comes to DDoS. Better to know them now than when you have 300Gps of traffic showing up at your door.”

Keanini advised: “Lastly, it goes without saying but if systems are vulnerable, and they are put on the Internet, they will be recruited to become a part of botnets. I think service providers should proactively scan their customers computers and help them resolve these vulnerabilities or block traffic to those services. It is a pay now or pay later type of situation because the bad guys will find this and it will still be the problem of customer and service provider – better to get ahead of the problem when you can schedule the work than to be called in to work when all hell breaks loose.”

Lamar Bailey, director of security research and development said: “The Spamhaus attacks should make other industries sit up and take notice. Spamhaus just demonstrated that even massive DDos attacks can be mitigated, they don’t have to take down your entire network. This is a critical lesson for enterprises, they need to plan for these types of attacks the same way they plan for data breaches. There are very good tools available to help mitigate these attacks; obviously enterprises should proactively add these to their security portfolio. The financial services industry in particular should sit up and take note.”

Whilst Andrew Storms, director of security operations: “Despite the work that has gone into making the Internet extremely resilient, these attacks underscore the fact that there are still some aspects of it that are relatively fragile. The Spamhaus attacks underscores how critical it is for organizations to be more proactive in addressing denial of service threats. We certainly can’t stop people from launching these kinds of attacks but we should invest more in research focused on the underlying issues. Given the scope of the attacks, government incentives supporting research into mitigation tools also makes sense.”