Black Lotus delivers award winning DDoS protection ranging from full network defense to website and server protection, 24/7/365. Learn more by visiting http://www.blacklotus.net or call (866) 477-5554.

Browsing "Older Posts"

Browsing Category "DNS-based DDoS"
Have you ever been the victim of a pickpocket? They often work in pairs, with one crook distracting you with conversation while the other relieves you of your wallet. Some cyber criminals are now using DDoS attacks to perpetrate “cyber pickpocketing” on a massive scale.
DDoS Attacks As Distractions
Think about what happens when you become the victim of a DDoS attack. Phones ring off the proverbial hook, customers complain about the breakdown in service, users panic, etc. – all while you’re trying to detect the source, stop the attack, and get your systems back up and running. Can you imagine a better distraction? Cyber criminals have already come to that realization, which is why they’re now using DDoS attacks to camouflage more sinister breaches. The next time your company experiences a DDoS attack, you may want to make sure it’s not just a smokescreen for the real crime.
How It Works
Unlike typical DDoS attacks, which often consume the network’s entire bandwidth, these distraction attacks leave just enough bandwidth open for hackers to accomplish their true purpose. Hackers count on everyone being so busy with the DDoS attack that they don’t notice the breach – or, if they do, they put it on the back burner until the DDoS attack is resolved. In the meantime, the hackers are busy extracting data, installing malware, or carrying out some other type of mischief. In addition, during traffic surges, some security protocols default to open in an attempt to keep things up and running. This creates the perfect opportunity for hackers to access just about anything they want.
In a variation of that scheme, some hackers use DDoS attacks to probe for system vulnerabilities. In this case, the DDoS acts as a Trojan horse, with the real threat going undetected. In 2013, attackers used this technique to steal $1 million in bitcoins from Danish payment processor BIPS.
Best practices
With the increase in “DDoS as distraction” attacks, your best bet is to avoid putting all of your IT resources into stopping the attack. Instead, assume that it might be a smokescreen for other illegal activity. Hold a team back and task them with monitoring the network for anything unusual. And, once you’ve successfully mitigated the DDoS attack, give your system a thorough checkup to make sure everything is in order.

No company is too big, too small, or too obscure to be the victim of a DDoS attack, whether it’s carried out as a nuisance or as camouflage for something else. Due to the many moving parts involved in data security, as well as the constantly evolving sophistication of hackers, many companies are deciding to outsource at least some parts of their data security to experts. And even the experts tend to specialize, with some focusing only on things like DDoS detection and mitigation. Whether you outsource your security or take care of things in-house, it’s critical to have detailed plans in place for both prevention and response. How confident are you in your network’s security?

DDoS Attacks: The New Trojan Horse

By Unknown → Monday, March 23, 2015
Looking at how much technology has changed our world over the years – even just over the past decade – can take your breath away. But, while the speed of incremental change is constantly accelerating, drastic overnight change is far less common. It still happens, however, and the Sony breach is one recent example. When that news hit, IT security professionals all over the world were slapped in the face with the reality of business disruption attacks, which can cripple an organization’s internal networks to the point where its employees can’t do business. The result was a wakeup call that initiated a shift from a “defend and detect” mode to “detect and respond”.
Cyber security as part of disaster management
What does this shift imply? For one thing, it means that more and more businesses will formulate documented responses to cyber attacks. Shawn Marck, CSO of cyber security firm Black Lotus, predicts, “Cyber security response will become a basic element of disaster and business continuity planning. What will you do if all of your emails and financial records are suddenly gone? What will be your PR response if negative information is stolen and exposed? What are your plans for retaining customers if your business is down for days at a time? If those customers leave, what will you do to get them back? And what support will you offer customers whose personal data is stolen? Companies that have a documented response plan will be at a distinct advantage over those that have to come up with it in the middle of a crisis.” Backing up what Marck says, research firm Gartner recently released a report saying that, by 2018, 40 percent of companies will have a formal plan in place for responding to cyber attacks, up from zero percent just a few years ago.
Shift toward detection and response
But disaster preparedness is just one piece of the puzzle. IT security professionals also need to have a plan in place for detecting an attack as soon as it begins and for stopping it before irreversible damage is done. Gartner vice president Paul Proctor says, “Entirely avoiding a compromise in a large, complex organization is just not possible, so a new emphasis toward detect and respond approaches has been building for several years, as attack patterns and overwhelming evidence support that a compromise will occur.” That brings cyber attack detection and mitigation to the top of the priority list for IT professionals in companies of all sizes.

Marck explains, “Standard detection strategies like pre-defined traffic patterns aren’t enough anymore, especially against the rising threat of application-layer attacks. Both detection and response strategies are becoming increasingly complex as these attacks become more sophisticated.”

In fact, many companies are choosing to outsource attack detection and mitigation. Some companies just don’t have the skills or resources to handle such a mission-critical project in-house. Others recognize the benefit of partnering with specialists who are plugged into that world and always up-to-date on the latest developments and attack methods. Regardless of whether you outsource your cyber security or do it in-house, it’s something that no business can afford to ignore.

The Next Evolution of Cybersecurity

By Unknown → Tuesday, March 17, 2015
Network security is something no one can take for granted these days. Not only are hackers becoming more sophisticated in their methods, they’re also becoming more sophisticated in how they use information once they access it. It’s not just about stealing credit card numbers, anymore. Eweek recently reported on five ways today’s hackers are pushing the envelope when it comes to wielding their power, and it’s worth taking notice.
Blackmail and extortion: The Sony breach showed us how awkward things can get when private communications become public. It’s a great setup for blackmail, especially if the victim is well known or has a lot to lose. Some hackers are digging up personal information on their victims and threatening to release it if their demands – usually money – aren’t met. A variation on this theme is extortion. Hackers use malware to lock people out of their own computers and demand money to let them back in.
The Internet of Things: It’s not just our computers and our phones that we have to worry about anymore. We now have all sorts of “things” connected to our networks: lighting, climate control, home security, etc. And very few of those things are secured. Determined hackers can find their way in and either use those devices to send out spam or use them as a gateway to the network of a home or office, providing access to all kinds of information.
Employee devices: Sophisticated hackers can use a single employee device to breach an entire company network. Now that almost everybody brings at least a personal cell phone to work, this is a growing risk for companies of all sizes.
Increasingly complex data: Credit card numbers are minor league. Sure, hackers can steal them, but they’re only good until the victim shuts down that account. Today’s hackers have access to much more personal information…information that can’t be easily changed. That includes personal contacts, medical information, shopping habits, and the like. All of that detailed information makes identity theft both easier and more effective.
Infrastructure: Our country’s infrastructure is complex and vulnerable, and both individual and state-sponsored hacktivists are taking advantage of that fact, sometimes to make a statement and sometimes to wreak havoc. One hacker can take down an entire electrical grid. Anything that depends on being connected is vulnerable: traffic control, air traffic control, subways, water filtration, and much more. This gives hacktivists the ability to make a huge impact with little effort.

Technology has changed our world, and I don’t think any of us want to go backwards. But all that connectivity also makes us vulnerable—as individuals, as businesses, and as a society. And it’s becoming more and more obvious that a single breach can have a widespread ripple effect. What if a hacker sold your company’s proprietary information to your biggest competitor? What about altering your company’s financial records to make it appear as if someone had committed fraud? The stakes are simply too high to make network security just another item on your to-do list. Whether you handle it internally or enlist the help of outside experts, your company’s security needs to be a top priority.

Hackers Are Using Stolen Data As a Weapon

By Unknown → Tuesday, March 10, 2015
The hackers at Lizard Squad have been busy again. Early in March, they used DNS poisoning to redirect traffic from Google’s Vietnamese page to a page advertising their own DDoS tool, the Lizard Stresser.
Despite the outrage of many users who weren’t able to access Google during the attack, it appears that no real harm was done. No servers crashed, and no personal information was stolen. Nonetheless, this case highlights the vulnerabilities inherent in the DNS system, and the next attack might not be so harmless.
How Hackers Exploit DNS Servers
DNS servers have often been referred to as the phone book of the internet, but they’re really more of a translator. They turn the human-friendly words (called “queries”) we type into our browsers into IP addresses, those strings of numbers that computers use to find web sites. This system is what keeps the internet running smoothly. But, if a hacker can answer a DNS server’s query with a fake response sooner than it gets the legitimate response, it’ll send traffic to the wrong website. Sometimes it’s just an annoyance, like the Lizard Squad attack on Google. But, far too often, users are redirected to a spoofed site that looks just like the real one and even has the right URL. So users enter their personal information, and the hackers strike gold.
Why DNS Servers Are An Enticing Target
It’s the caching capability built into DNS servers that makes them so tempting to hackers. Every time a server looks up an IP address, it “remembers” that information for a while, saving time on future queries. If it caches a fake address, everybody who comes along after that also gets sent to the fake address. So what originally affected only one person can end up affecting many more.
DNS poisoning isn’t the only way hackers exploit the DNS system. They can also use it to launch amplified DDoS attacks. In one type of attack, hackers get open DNS servers to do their dirty work for them. Instead of being limited to the queries they can send out on their own, they have a whole team working with them, making it easy to overwhelm the target site. Other times, they flood servers with requests for non-existent web sites, so that the servers keep sending queries for sites that never answer, tying up valuable resources.
What You Can Do
The smartest thing you can do for your business is to stop thinking, “It will never happen to me,” because the facts say otherwise. Pulling off a DNS attack is both easy and cheap, and, since some hackers do it just to prove they can, there doesn’t even have to be a reason. No company is too big, no company is too small, and no company is too obscure.  

Once you recognize your risk, your next job is to figure out what to do about it. Some businesses handle their security in-house, but more and more are outsourcing the task to specialists. Not only is network security a critically important job, it’s also a fight against a constantly moving target, as hackers’ strategies evolve. Regardless of who manages your security, they key is to make sure they’re the right people, have the right resources, and are totally plugged into the world of network security so that they’ll be out in front of new developments. Can your security team handle all of that?

Lizard Squad Goes After Google

By Unknown → Tuesday, March 3, 2015


Nearly all participants have a solution in place, but most are insufficient
SAN FRANCISCO--()--Black Lotus, a leader in availability security and provider of DDoS protection, released “DDoS Attacks: The Service Provider Impact,” a survey report showing the striking disparity between how threatened service providers feel by potential DDoS attacks and how prepared they are to mitigate one. The survey report shares data and insights into the types and sizes of attacks these service providers face, as well as how they respond to these attacks. The findings demonstrate that while almost all participants (92 percent) have some form of DDoS protection in place, it is insufficient to stop an attack before damage is done.
“DDoS attacks will continue to grow in scale and severity thanks to increasingly powerful (and readily available) attack tools, the multiple points of Internet vulnerability and increased dependence on the Internet. Enterprises have to move from thinking of DDoS as a possibility, to treating it as an eventuality.”
Most respondents incurred increased operational expenses due to DDoS attacks, with more than 35 percent of the providers surveyed indicating that they are hit with one or more attacks weekly. The respondents represented companies of all sizes, from small to large. The largest group represented in the survey was small companies of one to 999 employees worldwide (52 percent of all companies surveyed), with organizations of fewer than 250 employees (20 percent) as the largest subgroup.
Among the findings were:
  • 61 percent of providers feel that DDoS is a threat to their businesses.
  • Only 16 percent of the providers surveyed indicated that they had been rarely or never hit by a DDoS attack.
  • The top three industries with customers affected by DDoS attacks are managed hosting solutions (MHS), voice over IP (VoIP) and platform as a service (PaaS).
  • In case of a DDoS attack, 34 percent of the surveyed providers remove the targeted customer, and 52 percent temporarily null route or block the problem customer.
  • 64 percent of PaaS providers have been impacted by DDoS.
  • 56 percent of MHS providers have been impacted by DDoS.
  • 52 percent of infrastructure as a service (IaaS) providers have been impacted by DDoS.
One hundred and twenty-nine service providers responded to the electronic survey, which became available on August 2014 and was closed on Oct 31, 2014. IT-related administrators represent the largest occupational group among the respondents (65 percent), with network administrators (13 percent) and IT-related directors (10 percent) being the largest occupational groups selected. The relatively high participation of operational and network personnel in this survey, along with members of IT security teams, demonstrates that DDoS attacks are of prime interest to those responsible for network operations as well.
“DDoS attacks lasting hours or even minutes can lead to loss of revenue and customers, making DDoS protection no longer a luxury, but a necessity,” said Shawn Marck, co-founder and chief security officer of Black Lotus. “DDoS attacks will continue to grow in scale and severity thanks to increasingly powerful (and readily available) attack tools, the multiple points of Internet vulnerability and increased dependence on the Internet. Enterprises have to move from thinking of DDoS as a possibility, to treating it as an eventuality.”
Download DDoS Attacks: The Service Provider Impact for more details. An infographic of the results is available.
About Black Lotus Communications
Black Lotus Communications is a security innovator that pioneered the first commercially viable DDoS mitigation solutions. These advanced solutions enhance the security posture of small and medium businesses and enterprise clients while reducing capital expenditures, managing risk, ensuring compliance, and improving earnings and retention. Breakthrough developments at Black Lotus include the world's first DDoS-protected hosting network, the first IPv6 DDoS mitigation environment, and the first highly effective Layer 7 attack mitigation strategy. For more information, visit www.blacklotus.net or follow Black Lotus on Twitter at https://twitter.com/ddosprotection.

Contacts

Metis Communications
Justine Boucher, 617-236-0500
blacklotus@metiscomm.com

Survey Report: Majority of Service Providers Experienced DDoS Attacks, 85 Percent Experienced Customer Churn As a Result

By Unknown →
DNS servers are the traffic cops of the internet: They get everybody where they need to go. If DNS servers go down, users can’t reach the sites they need. If you’re a business, a DNS failure can stop you in your tracks and send your customers fleeing to your competitors.
DNS servers are critical – the internet wouldn’t function without them – but they can be used against you, too. Those same DNS servers that keep your business running can be exploited by hackers to launch massive DDoS attacks. These hackers can use open DNS servers to generate a flood of queries, which can quickly take the victim’s server offline.
Think of it like a fraudulent pyramid scheme. Let’s say you have a con artist who targets 10 potential victims every day. But then, let’s say you get each of those 10 victims to target 10 more potential victims…and so on. The number of potential victims increases exponentially. That’s amplification, and it’s exactly what happens when hackers launch a DNS-based DDoS attack.
Sometimes, hackers will use an array of vulnerable DNS servers to overwhelm a victim’s server with traffic. Instead of being limited to the number of queries they can send out on their own, they enlist a bunch of unwitting DNS servers to do it for them: amplification. And, if they intentionally design the queries to elicit a large number of responses, the impact is even greater.
Another way hackers use DNS servers to launch DDoS attacks is by flooding the servers with requests for non-existent web sites. The servers keep sending requests that are never answered. All of those open requests gobble up resources. And, if the server is caching bogus results, resources are depleted even faster.
Hackers can also bring down a DNS server by flooding it with fake responses. It keeps the server engaged with what is essentially “junk mail,” tying up resources that would otherwise be used for legitimate business purposes.
If that sounds like a lot of trouble for hackers to go to, it isn’t. These attacks are surprisingly easy and inexpensive to carry out, which is why they’re so common. According to an article in SC Magazine, 66 percent of U.S. organizations have experienced a DNS attack in the last 12 months. The survey, which included 300 IT decision-makers from companies with at least 1,000 employees, also revealed that 74 percent of the respondents who reported a DNS attack had experienced a DDoS attack aimed at slowing down their network or taking it completely offline.
Those statistics reveal the startling truth that, if you haven’t yet been the victim of a DDoS attack, you’re in the minority. Shawn Marck, CSO of cybersecurity company Black Lotus, agrees. “You will, eventually, be the target of a DDoS attack,” he explains. “It’s inevitable. Nobody is too big, nobody is too small, and nobody is too obscure. Sometimes it’s an unsatisfied customer; sometimes it’s a disgruntled employee. And, a lot of times, it’s just somebody who’s bored and wants to prove that they can do it. And when you’re dealing people who commit cybercrime as entertainment, there doesn’t have to be a reason. If you’re online, you’ll eventually be targeted.”
How secure is your company from DDoS attacks? Do you have protocols in place? What about contingency plans in case you are attacked? If you aren’t 100 percent sure of the answer to those questions, you need to become sure – today. Whether you do it in-house or partner with a cybersecurity firm, protecting your network from DDoS attacks just may be the most important thing you do this year.

Hackers Exploit DNS Servers to Launch Massive DDoS Attacks

By Unknown → Wednesday, February 25, 2015