Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

11/28/2016
05:30 PM
Sara Peters
Sara Peters
Slideshows
Connect Directly
Twitter
RSS
E-Mail
50%
50%

2016's 7 Worst DDoS Attacks So Far

Rise of booter and stresser services, mostly run on IoT botnets, is fueling DDoS excitement (but the pros aren't impressed).
Previous
1 of 9
Next

(Image source: by Roman Sigaev, via Shutterstock)
(Image source: by Roman Sigaev, via Shutterstock)

It takes a lot to surprise people who spend their time preventing DDoSes. Even the attack on DNS service provider Dyn last month "didn't shock ... by any means" Imperva's security group research manager Ben Herzberg and was "just another day at the office" to Arbor Networks' principal engineer Roland Dobbins.

"You don't look at [attackers'] intentions, you look at capabilities," Dobbins says. "Folks that do this for a living, we tend to be very cynical."  

If it seems that DDoSes had gone out of style for years, only to come raging back in a retro cybercrime fashion craze, that's not entirely accurate. According to the experts, DDoS attacks have been a constant, like Levi's 501 jeans. The recent headline-grabbing DDoSes are just glitzier, bedazzled versions of the same thing.  

Attacks fueled by Internet of Things botnets created with malware like BASHLITE or Mirai seemed rather exciting, but after all, Dobbins says, there were IoT botnets years ago - composed of Linux home routers instead of DVRs and CCTV cameras. They're not exactly new, they're just "the new hotness," as Akamai's senior security advocate Martin McKeay describes.

Nevertheless, Herzberg says "I do think 2016 was a transition year."

Why? The volume of large attacks increased. Akamai reported recently that there was a 138% year-over-year increase in DDoS attacks over 100 Gbps, and 19 of these "mega-attacks" in Q3 alone.

The cause: the rise of DDoSing-as-a-service and the proliferation of booter and stresser tools. Where once sophisticated DDoS attacks required sophisticated skills, these attacks can now be done by or at the behest of people with low to no hacking ability. There are more players in the game now with better tools at their disposal.

And, by the way, most of those direct DDoS-for-hire services are run on IoT botnets.

If it seems that the attacks must change the way every defender does everything, that's not entirely true either. Dobbins says the best practices for making DNS architecture and organizations' network infrastructure resilient to DDoS attacks are essentially the same as they were 20 years ago or more; the trouble is getting those best practices deployed.

"If could make everything as resilient as it possibly could be, we would still have DDoS attacks, but their impact would be many magnitudes lower," Dobbins says. Many organizations do not even take into account DDoS in their business continuity planning, he says. 

Experts concede that even if a DDoS is unsurprising and uninventive, it can also be quite disruptive if the target isn't prepared to respond.

In that spirit, here are the worst, most definitive DDoS attacks of 2016 so far.

 

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Previous
1 of 9
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
lorraine89
50%
50%
lorraine89,
User Rank: Ninja
12/7/2016 | 8:04:44 AM
Cyber security
Well this just goes on to show how much of our data be it stored in our systems or browsing online is vulnerable and susceptible to being hacked or mistreated by malicious hands. Therefore it is always important to secure online footprints and privacy and what best way to do that than deploying secure vpn server like PureVPN which provides online encrypted connections. They have some deals going from what I read on my last visit to their website. 

www.purevpn.com/order
Cerber 5
50%
50%
Cerber 5,
User Rank: Apprentice
12/6/2016 | 4:04:03 PM
Goldeneye ransomware attacks German users
There is another cyber attack right now in Germany - Goldeneye ransomware (successor of the Petya and Mischa ransomware viruses).
Nanireko
50%
50%
Nanireko,
User Rank: Apprentice
12/6/2016 | 10:55:58 AM
More big attacks
Some more really big DDoS attacks should have been mentioned here:

1) Thousands of TalkTalk and Post Office customers have had their internet access cut by an attack targeting certain types of internet routers. A spokeswoman for the Post Office told the BBC that the problem began on Sunday and had affected about 100,000 of its customers.

2) As many as 900,000 Deutsche Telekom customers were knocked offline in Novermber as an attempt was made to hijack broadband routers into a botnet, critical router flaw exploited.
Aviation Faces Increasing Cybersecurity Scrutiny
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/22/2019
Microsoft Tops Phishers' Favorite Brands as Facebook Spikes
Kelly Sheridan, Staff Editor, Dark Reading,  8/22/2019
MoviePass Leaves Credit Card Numbers, Personal Data Exposed Online
Kelly Sheridan, Staff Editor, Dark Reading,  8/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-6154
PUBLISHED: 2019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
CVE-2019-5594
PUBLISHED: 2019-08-23
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
CVE-2019-6695
PUBLISHED: 2019-08-23
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6.2.1 may allow an attacker to implant third-party programs by recreating the image through specific methods.
CVE-2019-12400
PUBLISHED: 2019-08-23
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this im...
CVE-2019-15092
PUBLISHED: 2019-08-23
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.