Vulnerabilities / Threats
8/21/2013
02:49 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Natural Disasters Cause More Downtime Than Hackers

Study of 79 Internet and telephony outages in 18 European countries found that storms -- especially snowstorms -- caused significantly longer outages than cyberattacks.

When it comes to downtime, snow triggers longer outages than hack attacks.

That's one disaster recovery -- and planning -- takeaway from the latest "Annual Incident Reports" study, published Tuesday by the European Network and Information Security Agency (ENISA).

The report is based on 79 incident reports of severe outages of electronic communication networks or services that occurred in 2012. ENISA defines serious incidents -- which European government agencies are required to report -- on a sliding scale, ranging from events that last at least an hour and affect 15% or more users, up to events that last more than eight hours and affect 1% or more of all users.

All told, 18 European countries reported having a total of 79 "significant incidents" to ENISA, while nine other countries said they had no such incidents.

[ Twitter users should reassign access to third-party apps. Read more: Hacker Leaks 15,000 Twitter Access Credentials, Promises More. ]

Downtime is a major concern for businesses and government agencies. When systems are down, employee productivity plummets, sales get put on hold, subscribers can't be billed and emergency services can't be reached.

The report assessed four different types of service interruptions: fixed telephony and fixed Internet, and mobile telephony and mobile Internet. For incidents in all four services, hardware failure was the most common cause of service disruption, according to the report. "The second most common cause for fixed telephony was [a] software bug," it read. "Half of those incidents affected VoIP." For fixed Internet outages, cyber attack was the second most common cause, reported ENISA. Finally, software bugs were the second most common cause of outages for mobile telephony and mobile Internet.

But the outages with the longest recovery time were triggered by incidents caused by natural phenomena -- mainly storms and heavy snowfall, reported ENISA. On average, such outages lasted about 36 hours.

The majority of outages -- comprising about half of all reports -- involved mobile telephony or mobile Internet and affected an average of 1.8 million people in every incident.

In 75% of outages, the leading root cause was listed as "system failure." "Hardware failures were the most common cause, followed by software bugs," reported ENISA. "The assets most often affected by system failures were switches -- e.g., routers and local exchange points -- and home location registers." The latter refers to databases of authorized mobile phone subscribers.

The report detailed a number of actual incidents, ranging from the natural and the accidental to human error and malicious insiders. As an example on the human-error front, one telephony employee committed a system configuration error that prevented landline users from making outgoing international calls to Western Europe for four hours, which was solved by reconfiguration and a reboot of the system involved. Meanwhile, a 14-hour outage involving 40,000 VoIP users was triggered by the service provider transitioning to a new system and finding it couldn't handle the volume of related registration requests being issued by subscribers' devices.

On the accident front, four submarine cables linking two islands being accidentally cut by a ship's anchor, leading to a temporary outage.

On the malicious front, a distributed denial of service (DDoS) attack against a mobile Internet provider prevented 2.5 million users from connecting to the Internet for up to two hours. After mitigating the attack, the provider put stronger DDoS defenses in place to withstand repeat attacks.

Finally, a former employee of an Internet service provider deliberately set fire to a switching system, which was used for providing fixed Internet service to around 10,000 subscribers, according to ENISA. Service was restored some 36 hours later.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ChrisMurphy
50%
50%
ChrisMurphy,
User Rank: Apprentice
8/26/2013 | 7:54:47 PM
re: Natural Disasters Cause More Downtime Than Hackers
The biggest fear from hackers tends to be more about theft (intellectual property in particular) rather than downtime. So I guess this doesn't surprise me that much.
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
8/22/2013 | 2:14:33 PM
re: Natural Disasters Cause More Downtime Than Hackers
IT would be interesting to do a study of spend on BC/DR vs. security at the companies affected. In our surveys we constantly see disaster recovery short-changed, with testing done annually at best and a lack of realism.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-0460
Published: 2014-04-16
The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

CVE-2011-0993
Published: 2014-04-16
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.

CVE-2011-3180
Published: 2014-04-16
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

CVE-2011-4089
Published: 2014-04-16
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

CVE-2011-4192
Published: 2014-04-16
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."

Best of the Web