Attacks/Breaches
3/16/2011
01:46 PM
50%
50%

Denial Of Service Attacks Increased Sharply In 2010

DDoS attacks surpass SQL injection to become most prevalent attack vector, security vendor Trustwave reports.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches

Between the first and second half of 2010, distributed denial-of-service (DDoS) attacks grew to surpass SQL injection attacks as the number-one attack vector against large businesses and organizations, according to a report from information security vendor Trustwave.

The study released Monday found that the principle drivers for Web attacks appear to be to causing Web site downtime (in 33% of cases), defacement (15%), stealing information (13%), planting malware to infect end clients (9%), and spreading disinformation (9%).

Despite the prevalence of downtime, most attacks appear to be profit-driven, and the Trustwave study found that attack outcomes largely mirrored this goal. For financial sector organizations, for example, 64% of attacks resulted in monetary loss, with 59% of firms admitting that they lacked robust enough authentication, and 36% saying that they'd been hacked using stolen credentials. Meanwhile, in the retail sector, 27% of attacks resulted in credit card data leakage, and SQL injection attacks were the principle method of attack.

Likewise, government Web sites most frequently fell due to SQL injection attacks (used in 24% of cases) and because of improper Web application input handling (for 26% of organizations). Thankfully, the principle outcome (in 26% of cases) was only Web site defacement.

As noted, DDoS attacks have become the principle hacking technique (in 32% of cases), followed by SQL injection (21%) and cross-site scripting (9%). Brute force, cross-site request forgery, process automation, and known vulnerability attacks were also seen, though less frequently.

Unfortunately, DDoS attacks are becoming harder to stop. In particular, newer types of attacks often target the Web application layer. Instead of overwhelmingly a network with packets, attackers can employ a smaller number of specially crafted requests -- using HTTP, HTTPS, SMTP, FTP, and similar protocols -- to produce a denial of service. For example, Slowloris, a free tool released in 2009, uses time-delayed HTTP headers to prevent HTTP connections from expiring, until servers simply run out of bandwidth.

According to Trustwave's report, "the bottom line is that the overall amount of traffic needed to potentially take down a Web site is much less than is required to flood the network pipe leading to the Web server."

Trustwave isn't the first firm to spot the rise in DDoS attacks or variation in techniques. Last month, an Arbor Networks study blamed botnets for a noticeable increase in DDoS attack sophistication and frequency. Notably, it found that DDoS attack bandwidth increased by 102% during 2010, and rose by a staggering 1,000% from 2005 and 2010.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Join Dark Reading community editor Marilyn Cohodas and her guest, David Shearer, (ISC)2 Chief Executive Officer, as they discuss issues that keep IT security professionals up at night, including results from the recent 2016 Black Hat Attendee Survey.