Cyber Security Institute

§ Current Worries

Top 3 Worries

  • Regulations
  • Old Firewall Configurations
  • Security Awareness

§ Listening

For the best information

  • The underground
  • Audible
  • Executive Excellence
  • Music (to keep me sane)

§ Watching

For early warnings

  • 150 Security Websites
  • AP Newsfeeds
  • Vendors

Wednesday, January 23, 2013

DNS attacks increase by 170%

Radware’s latest report highlights server-based botnets and encrypted layer attacks as just two of the new attack tools challenging organizations during DDoS attacks.  While security organizations have focused their efforts and attention on the pre and post-phases of defense, attackers now launch prolonged attacks that last days or weeks.  This has created a vulnerable blind-spot as defenders lack the capabilities and resources to mitigate attacks in the “during” phase which attackers can exploit to their advantage.

The shift from single-server attacks to the use of multiple servers in different geographic locations has allowed attackers to quickly and effectively launch more powerful DDoS attacks than ever before.  Just a few attacking servers can produce the same attack traffic as a large number of client botnets, with the 24/7 availability of servers allowing for greater reliability as well as command-and-control.  In 2013, Radware expects this method to gain in popularity, requiring that organizations make sure their defense architecture can withstand these scaled up attacks.

The numbers are staggering – with 58 percent of attacks scoring a 7 or higher in complexity (out of 10), as compared to just 23 percent of attacks in 2011.  Though conventionally associated with security on the web, hackers have managed to weaponize the encryption layer, using it to launch application-level and SSL attacks that can escape detection and remain hidden until its already too late.

With some of the worlds largest institutions victimized by cyber attacks in 2012, the question remains as to why many of these organizations continue to be vulnerable.  The fact remains that less than a quarter of all organizations surveyed invest their efforts in mitigating attacks as they’re happening – a fact exploited by hackers.  In 2013, Radware recommends that organizations dedicate resources to creating a “security war room” equipped to dynamically respond to and handle persistent security attacks during all phases of an attack and adopt a three-phased security approach.

The supply chain includes took kits and for-hire services that are available to anyone with minimal coding or advanced hacking skills for as little as $10 for a ransomware attack tool.

Key findings include:
- Server-based botnets represent a new and more powerful order in the DDoS environment.
- The number of DDoS and DoS attacks lasting more than one week doubled in 2012.
- Encrypted layer attacks fly below the radar – and can’t be ignored.
- In today’s security environment, most organizations are bringing a knife to a gunfight.
-The DIY phenomenon.

Link: http://www.net-security.org/secworld.php?id=14285

Posted on 01/23
TrendsWarningsPermalink