Welcome Guest. | Log In | Register | Membership Benefits

Más DDoS: More Powerful, Complex, And Widespread

New DDoS reports highlight evolving M.O. of DDoS and DoS attacks and increased firepower

Feb 07, 2012 | 07:40 PM | 

By Kelly Jackson Higgins
Dark Reading
Three DDoS reports published this week reveal how more powerful attacks are becoming the norm, that hacktivism is the main inspiration now rather than extortion -- and anyone can be a victim, not just high-profile organizations.

Arbor Networks, Radware, and Prolexic each released reports detailing trends and data in distributed denial-of-service (DDoS) and regular denial-of-service (DoS) attacks. Among the trends in these often-debilitating attacks on a victim's network infrastructure, website, or other application-layer services is that the impetus for these attacks now is more about hacktivism and vandalism versus extortion -- an old-school motivation -- and no one is immune from becoming a target.

"It was stunning to us what motivated these DDoS attacks," says Roland Dobbins, solutions architect at Arbor and one of the authors of Arbor's "World Wide Infrastructure Security Report for 2011." "It was a surprise to us, but at the same time it jives with our individual experiences and working with service providers around the world. About half the DDoS attacks I personally helped defend against were ideologically motivated."

Dobbins says this is a game-changer. "This really alters the threat landscape for any organization that's Internet-connected. If anyone has a political or ideological ax to grind against an organization or the country where they are headquartered," they are at risk, he says.

Radware's "2011 Global Application and Network Security Report" echoed some of the same findings about DDoS and DoS attacks in that hacktivists were the main perpetrators, with 22 percent of attacks; 12 percent were angry users; 7 percent, a competitor; and 4 percent, extortion. Half of the attacked organizations surveyed by Radware didn't know why they were targeted.

Arbor also found that attackers now have so much firepower that high-volume attacks are no longer a rarity. DDoS attacks in the 10-Gbps range were up, with 13 percent reporting them, and 25 percent of victims say they were hit by attacks that outpaced the total bandwidth of their data center.

"10-Gbps and under attacks are no longer very rare -- they are very commonplace," Dobbins says. "And the broader deployment of [anti-] DDoS technologies [by organizations] is causing attackers to up their game, so it's an arms race.

Prolexic's "Quarterly Attack Report for Q4 2011" also shows a marked increase in more powerful DDoS attacks. The average attack bandwidth in the fourth quarter was 5.2 Gbps, up from 2.1 Gbps in the third quarter; that's an increase of 148 percent, according to Prolexic. Average attack bandwidth jumped 136 percent last year to 2.6 Gbps versus 1.1 Gbps in 2010.

But size doesn't always matter. Radware's report says most organizations don't suffer from catastrophic DDoS attacks: Smaller, less powerful ones can cause more damage with less bandwidth. Some 76 percent of attacks in its survey came in at under 1 Gbps, with 32 percent less than 10 megabits-per-second, and nine percent more than 10 Gbps.

Meanwhile, application-layer attacks are on the upswing. "There is a rise in the sophistication and prevalence of application-layer attacks," Arbor's Dobbins says. "Attackers are not just launching high-bandwidth, high-packet-based attacks. They are doing research and figuring out how to [attack] the app running on the server ... causing websites to fall over."

According to Radware, 56 percent of DoS-type attacks last year went after applications, and 46 percent, the network. Financial services was hit the most, with 28 percent of the attacks, followed by government (25 percent) and gaming sites (25 percent).

Attackers aren't just going after one specific application or HTTP. They are mixing two or more vectors, such as HTTP, SMTP, HTTPS, DNS, SNMP, and IRC, according to Arbor's Dobbins.

Some attacks used up to five different attack vectors in a campaign, according to Radware. And the big bandwidth-sized attacks aren't necessarily the most damaging. A smaller HTTP attack can do more damage than a massive UDP flood attack.

And Prolexic saw shorter attack intervals. "We have seen a trend toward shorter overall attack duration, but with unprecedented high packet-per-second volume and lethal attack signatures,” says Paul Sop, chief technology officer at Prolexic. "This is a devastating cocktail that can quickly bring down even well-protected sites and their mitigation providers. We are starting to see packet-per-second attack volumes that are simply off the charts.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Security Services Reports

report Using Service Providers To Manage DDoS Threats
When it comes to the battle against distributed denial-of-service attacks, you are not alone. With the increasing use of third-party service providers, your organization likely has a huge arsenal of bandwidth, technology and know-how at its disposal. The challenge is to effectively marshal those resources among your providers and integrate them with your own security measures into a strategic and comprehensive DDoS protection plan.

report Hosted Web Security Services: Block Malware Before Your Border
Security service providers are now delivering a wide range of packaged offerings, including Web content filtering, anti-malware, data leak prevention, and many other capabilities. How can your organization take advantage of these Web security services, and how can you choose the right provider? This Dark Reading Tech Center report offers a look at these services and some recommendations on how best to implement them.

report You've Got (Secure) Mail: Using Service Providers to Boost Protection
The SaaS market is still in its infancy, but hosted e-mail security firms are leading the way, thanks to ease of implementation and many obvious benefits. Still, these services are not without risks. In this Dark Reading Tech Center report, we'll discuss how to determine what mix of in-house and hosted email security makes sense for your organization.

Other reports from the Security Services Tech Center:

Related Content

Establishing a Formal Cyber Intelligence Capability
Organizations are realizing that advanced intelligence capabilities consistently deliver substantial cost savings - with proactive insights on true threats, the intelligence to avoid false alarms, and the system and application availability required to preserve revenues and customer loyalty. But achieving these benefits requires organizations to establish a formal cyber intelligence capability. Read this whitepaper to learn about a proven, repeatable process with clearly established steps for setting up an in-house cyber security intelligence operation.

DDoS Mitigation: Best Practices for a Rapidly Changing Threat Landscape
Although DDoS attacks have become a mainstay of hackers' arsenals, their profile has changed considerably in the past year, making them an even greater threat to companies that conduct business online. DDoS attacks are larger, stealthier, more targeted, and more sophisticated than ever. Get best practices to enable your organization to keep pace with DDoS attacks while minimizing impact on business operations.

2012 Cyber Crime Threats and Trends
Get the highlights of 2011 cyber security trends and how those trends and others might unfold in 2012. This report is a strategic complement to daily tactical intelligence reports and provides IT security and business operations with actionable and relevant decision support.

Using Hybrid Routing to Optimize DNS Resolution Performance and Reliability
To create a satisfactory end user experience, enterprises must ensure that DNS resolution is fast and reliable. Learn more about how using a hybrid routing solution can greatly maximize performance while minimizing latency-and address your business' specific needs along the way.

A Cost Analysis of Approaches To DDoS Protection.
All organizations with an online presence or dependence on Internet-based systems need to fortify their defenses against DDoS attacks. DDoS can cost an organization in tangible losses and in more subtle ways. Read this whitepaper for a deeper perspective on the cost benefits of a dedicated, cloud-based DDoS service over an in-house hardware solution or over-provisioning through your ISP.




Featured Webcasts
Featured Whitepapers
Featured Reports