Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

ABTV

8/25/2017
04:25 PM
Curtis Franklin
Curtis Franklin
Curt Franklin
50%
50%

DDoS Trends Show Big Impact From Fewer Servers

A change in control networks means that this quarter saw DDoS attacks from fewer endpoints, each having a bigger impact.

Does "quality over quantity" matter when the subject is criminal activity? That's a key question raised by the latest edition of Akamai's Second Quarter, 2017 State of the Internet/Security Report, released this week.

According to the report, issued by the company for nearly a decade, the number of DDoS attacks is up sharply (28%) over the first quarter of 2017, but the number of devices used in the attacks is down even more dramatically -- from an average of 595,000 devices used per attack in Q1 to an average of 11,000 per attack in Q2 -- a drop of 98%.

In a telephone interview with Martin McKeay, Akamai security advocate and senior editor for the report, he told Security Now that the drop in the number of systems used to generate traffic did not mean that the amount of traffic used in the attacks also went down.

"The amount of traffic is comparable to a lot of the Marai attacks but it's being done with a fraction of the number of compromised systems," McKeay said. The difference, he explained, is the rise in the number of attacks making use of a malware variant called PBot to generate the traffic on systems -- and the systems on which PBot runs.

Where Marai took control of IoT end points like thermostats, lightbulbs and other small "smart" devices, PBot looks for larger quarry. "They were using things like Apache web servers and other servers like that," McKeay said. "They're taking advantage of devices or of systems that are designed to have a high bandwidth, designed to be able to respond with a lot of traffic and [where that traffic is] going to be viewed as normal."

The nature of the systems PBot uses has implications beyond just the possible volume of traffic. "Unless you have a SysAdmin that is really paying attention to their systems or seeing slowdowns because of the amount of traffic that PBot is sending, they could maintain control of these for some time," McKeay explained. And ultimately, that control could make for truly massive DDoS attacks.

"If Pbot or some of these other variants start making larger uses of the bandwidth of those systems they have compromised -- if they become more virulent -- then they can actually create much larger attacks," McKeay said. "We saw a 75 [gigabit per second] attack this quarter but it's almost certain that, within the next quarter or two, we're going to see some new attacks that are going to dwarf the attacks that we've seen in the past."

"If you'd asked me a year ago I would probably have expected attacks to be breaching five or six hundred gigs [per second] now. But I've now seen the Marai bot net and I think that by the end of the year it's quite likely that we might see a terabit attack on our network," he said. And that scale of attack is available to a much wider range of criminal actors.

McKeay explained that Akamai researchers have been looking at the command and control structure of the Marai bot net. After studying traffic on the control network for nine months, they were able to reach some conclusions about how the network of zombie traffic generators is being used.

"There's a number of the command and control structures that are hitting one or two maybe five targets. So a relatively small cluster of targets," McKeay said, telling Security Now that this was the sort of pattern you would expect if the developer of a bot net was using the net for their own purposes. "Then you've got a lot of the command and control structures that are sending out commands to hit dozens to 100 or more targets. And what that tells us is that command and control structure is being used as a 'pay for play' or for-rent bot net," he said.


Track the heartbeat of the virtualization movement with Light Reading at the NFV & Carrier SDN event in Denver. There's still time to register for this exclusive opportunity to learn from and network with industry experts -- communications service providers get in free!

Someone who wants to damage the business of a rival or enemy can rent the bot net's services for a few minutes or a day. But the purpose of the network isn't to punish a single target -- it's to be a commercial resource that can be turned to profit for the owner. "They're using it to make money," McKeay said. "I mean, we've known that they existed. We suspected that Marai was being used but this has showed us that it almost certainly is one of the latest in for-pay DDoS attacks."

Related posts:

— Curtis Franklin is the editor of SecurityNow.com. Follow him on Twitter @kg4gwa.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15058
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
CVE-2020-15059
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
CVE-2020-15060
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2020-15061
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
CVE-2020-15062
PUBLISHED: 2020-08-07
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.