Attacks/Breaches
3/16/2011
01:46 PM
50%
50%

Denial Of Service Attacks Increased Sharply In 2010

DDoS attacks surpass SQL injection to become most prevalent attack vector, security vendor Trustwave reports.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches

Between the first and second half of 2010, distributed denial-of-service (DDoS) attacks grew to surpass SQL injection attacks as the number-one attack vector against large businesses and organizations, according to a report from information security vendor Trustwave.

The study released Monday found that the principle drivers for Web attacks appear to be to causing Web site downtime (in 33% of cases), defacement (15%), stealing information (13%), planting malware to infect end clients (9%), and spreading disinformation (9%).

Despite the prevalence of downtime, most attacks appear to be profit-driven, and the Trustwave study found that attack outcomes largely mirrored this goal. For financial sector organizations, for example, 64% of attacks resulted in monetary loss, with 59% of firms admitting that they lacked robust enough authentication, and 36% saying that they'd been hacked using stolen credentials. Meanwhile, in the retail sector, 27% of attacks resulted in credit card data leakage, and SQL injection attacks were the principle method of attack.

Likewise, government Web sites most frequently fell due to SQL injection attacks (used in 24% of cases) and because of improper Web application input handling (for 26% of organizations). Thankfully, the principle outcome (in 26% of cases) was only Web site defacement.

As noted, DDoS attacks have become the principle hacking technique (in 32% of cases), followed by SQL injection (21%) and cross-site scripting (9%). Brute force, cross-site request forgery, process automation, and known vulnerability attacks were also seen, though less frequently.

Unfortunately, DDoS attacks are becoming harder to stop. In particular, newer types of attacks often target the Web application layer. Instead of overwhelmingly a network with packets, attackers can employ a smaller number of specially crafted requests -- using HTTP, HTTPS, SMTP, FTP, and similar protocols -- to produce a denial of service. For example, Slowloris, a free tool released in 2009, uses time-delayed HTTP headers to prevent HTTP connections from expiring, until servers simply run out of bandwidth.

According to Trustwave's report, "the bottom line is that the overall amount of traffic needed to potentially take down a Web site is much less than is required to flood the network pipe leading to the Web server."

Trustwave isn't the first firm to spot the rise in DDoS attacks or variation in techniques. Last month, an Arbor Networks study blamed botnets for a noticeable increase in DDoS attack sophistication and frequency. Notably, it found that DDoS attack bandwidth increased by 102% during 2010, and rose by a staggering 1,000% from 2005 and 2010.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-8626
Published: 2014-11-22
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding...

CVE-2014-8710
Published: 2014-11-22
The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

CVE-2014-8711
Published: 2014-11-22
Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow remote attackers to cause a denial of service (application crash) via a crafted amqp_0_10 PDU in a packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?