IMPERVA SECURITY PREDICTIONS FOR 2015 » Imperva has been in the business of protecting the high-value applications and data assets at the he... Mimecast ranked among the fastest growing techno... » London, UK: Mimecast has been ranked on the Deloitte Technology Fast 500 EMEA 2014, a ranking of the... gateprotect once again awarded the quality label ‘... » Hamburg: gateprotect GmbH, the German IT security specialist and member of the Rohde & Schwarz Group... The U.S. and Cuba » The White House, Washington Yesterday, after more than 50 years, we began to change America's rela... Why is an integrated network health solution criti... » Networks have become a strategic business asset that glues together the data, the applications, and ... Nuix joins McAfee security Innovation Alliance P... » LONDON, UK: Nuix has joined the McAfee Security Innovation Alliance program. Nuix and McAfee are now... IGEL updates Windows Embedded firmware and expands... » Reading, UK: IGEL Technology has updated its firmware for its Windows Embedded Standard 7 thin clien... ForgeRock reveals 2015 technology predictions » Bristol: ForgeRock Inc. has revealed its 2015 technology predictions. The company expects to see inc... Lancope unveils newly enhanced, world-Class cust... » Company has increased its investment in customer success by 150 percent this year LONDON UK: Lanco... ANNUAL ARMED FORCES COVENANT REPORT PUBLISHED » THE Armed Forces Covenant Annual Report has been presented to Parliament today and details the progr...

CLICK HERE TO

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

Lessons learnt from SpamHaus DDoS attack

Vigilance can report that last week, as part of the Spammer-Anti-Spammer wars, an attack on Spamhaus was created using a DNS amplification attack on highly rated DNS servers, the attack used Botnets to send an initial reflection request to the DNS Servers, which then generated the actual traffic. Today, although we are not sure if the same vector of attack was used again, the attack was able to draw enough web traffic to Spamhaus to reach a reported peak of 300Gbps of DDoS – a respectable number indeed. It is clear that proper DNS Server monitoring and configuration should have deflected the attack at an early stage. The DNS Attack vector showed again the effectiveness of using servers as initial attack vectors rather than a user-based botnet.

 

Spamhaus cyber attack

In his reaction to the news around the Spamhaus cyberattack, which researchers are describing as the world’s largest ever cyber attack and is slowing down global internet services, Tim Keanini, CRO at nCircle, said: “While this is making the news, this is the day in the life of a service provider as these attacks are common place. Yes, this one is larger but again that is a product of more and more computers get compromised to become a part of these botnets and these computers are being connected at higher and higher speeds each year.”

Mr Keanini added:“Application amplification is also something that has been around for quite some time. Anytime you have a situation where 1 packets can be spoofed and sent to a destination that will return 2 or more packets (returning 5 gets you a 5:1 amplifier), you can be damn sure that DDoS’er will know how to leverage it. This also stresses the importance of monitory ingress/egress filtering at the border routers to make it impossible to spoof addresses. My point is that all the counter measures for this type of attack once it has begun will be at the service provider level so get to know your service provider and understand their practices when it comes to DDoS. Better to know them now than when you have 300Gps of traffic showing up at your door.”

Keanini advised: “Lastly, it goes without saying but if systems are vulnerable, and they are put on the Internet, they will be recruited to become a part of botnets. I think service providers should proactively scan their customers computers and help them resolve these vulnerabilities or block traffic to those services. It is a pay now or pay later type of situation because the bad guys will find this and it will still be the problem of customer and service provider – better to get ahead of the problem when you can schedule the work than to be called in to work when all hell breaks loose.”

Lamar Bailey, director of security research and development said: “The Spamhaus attacks should make other industries sit up and take notice. Spamhaus just demonstrated that even massive DDos attacks can be mitigated, they don’t have to take down your entire network. This is a critical lesson for enterprises, they need to plan for these types of attacks the same way they plan for data breaches. There are very good tools available to help mitigate these attacks; obviously enterprises should proactively add these to their security portfolio. The financial services industry in particular should sit up and take note.”

Whilst Andrew Storms, director of security operations: “Despite the work that has gone into making the Internet extremely resilient, these attacks underscore the fact that there are still some aspects of it that are relatively fragile. The Spamhaus attacks underscores how critical it is for organizations to be more proactive in addressing denial of service threats. We certainly can’t stop people from launching these kinds of attacks but we should invest more in research focused on the underlying issues. Given the scope of the attacks, government incentives supporting research into mitigation tools also makes sense.”