Black Lotus delivers award winning DDoS protection ranging from full network defense to website and server protection, 24/7/365. Learn more by visiting http://www.blacklotus.net or call (866) 477-5554.

Browsing "Older Posts"

Browsing Category "Threat Report"
One of the most profound societal effects of technology has been democratization. In other words, technological advances have blown away many traditional barriers to entry for all kinds of endeavors. Thanks to Google, for instance, anybody with internet access can find the answer to almost any question within seconds. You can explore the Sistine Chapel without leaving your living room. You can plan your own vacation from your kitchen table rather than relying on a travel agent. Most of the time, that’s a good thing. Unfortunately, one of the things that’s been democratized by easy access to technology is cybercrime.
We used to think of hackers as antisocial geniuses, pulling off technical feats that were totally incomprehensible to the average user. But that’s not true anymore. Today, even a college kid can take down a huge company from his dorm room. And, thanks to tools that are out there for anyone who knows they exist, he can do it without missing a single minute of The Walking Dead.
Case in point: The Christmas Day DDoS attacks on the Sony PlayStation Network and Microsoft XBOX Live. XBOX Live was down for three days, and PlayStation Network was down for five. As it turned out, the whole thing was a publicity stunt, designed to draw attention to Lizard Stresser, a new DDoS-for-Hire product developed by Lizard Squad. As reported in Venturebeat, the tool came complete with marketing text: “This booter is famous for taking down some of the world’s largest gaming networks such as Xbox Live, Playstation Network, Jagex, BattleNet, League of Legends, and many more! With this stresser, you wield the power to launch some of the world’s largest denial of service attacks.” And the prices were rock-bottom, with the mid-range package costing $130 to take down a site for over eight hours.
Since then, the site has been taken offline, and several of the hackers have been arrested. But that doesn’t mean the threat is over, because there are plenty of others eager to step in and fill gap. Thanks to cybercrime as a product, the field of people capable of launching a devastating DDoS attack has just grown exponentially, as has the challenge facing IT staff everywhere.
The task of fending off DDoS tasks is too big, too varied, and too subject to lightning-fast change for businesses to treat it as just another IT project. The irony would be almost funny if the threat wasn’t so big: As DDoS attacks become something available to anybody with a few dollars to spend, DDoS protection is becoming a specialty service, provided by companies that focus on DDoS and nothing else. DDoS attacks are for the masses, and DDoS protection is for the experts.
Don’t waste another day. If you’re not absolutely certain you can handle DDoS protection in-house, find a provider you trust. Look for a company that offers multi-layer protection, constant updates to protect against the latest strategies, and 24/7 emergency service in case your company does become the victim of a DDoS attack. It’s not enough to just protect you from attacks; you need somebody who can get you back online as quickly as possible if something slips through. If your web site is mission-critical, your DDoS protection has to be mission-critical, too.

###

The Democratization of Cybercrime

By Unknown → Wednesday, February 18, 2015






Peak bit volume drops 87 percent in Q3 2014, coinciding with departure from amplification attacks


SAN FRANCISCO--()--The newest up-and-coming countries of origin for distributed denial of service (DDoS) attacks will be Vietnam, India and Indonesia in 2015. While these countries don’t have the necessary bandwidth to launch massive DDoS attacks, the volume of compromised end point devices, such as mobile phones, make them prime sources of new botnets. China topped the list of leading sources of DDoS attacks in Q3 2014, followed by the United States and Russia. These findings were issued today via Black LotusQ3 2014 Threat Report. Black Lotus, a leader in availability security and provider of DDoS protection, compiles its quarterly Threat Reports by drawing on the latest attack data from its network logs and analyzing the results for trends in attack size, duration, method, source and other characteristics.
“DDoS attacks continue to fall in size and frequency in 2014, making them easier to handle for tier one carrier networks with excess capacity, but still tricky to manage for organizations with less bandwidth”
The Black Lotus Q3 2014 Threat Report, which covers DDoS attack data between July 1 and September 29, 2014, shows that Black Lotus customers experienced a 87 percent decrease in bit volume attacks compared to the rest of 2014. These changes can be attributed to attackers resorting to more complex attacks, such as SYN floods and application layer attacks, instead of amplification attacks. The Black Lotus mitigation team expects attackers will continue to resort to non-amplification attacks when there are not enough vulnerable systems available to exploit for reflection methods, and they anticipate a rise in mobile DDoS attacks as emerging countries increase smartphone subscriber usage. Therefore, IT managers and security teams will need to adjust strategies to handle targeted, multi-vector attacks to thwart outages rather than volumetric methods, while preparing against growing packet volume that may saturate their existing DDoS safeguards.
The report findings also show that:
  • The largest bit volume DDoS attack observed during the report period was 54.4 Gbps on September 14, a marked decline in volume since the beginning of 2014, due to NTP and other types of amplification attacks becoming more difficult to execute without sufficient NTP vulnerabilities. Rather than using volumetric attacks to overwhelm servers, organizations should be wary of cyberattackers targeting crucial ports to thwart legitimate traffic from reaching online destinations.
  • 58 percent of the 255,564 attacks observed during Q3 2014 were regarded as severe, nearly half of which were SYN flood attacks and 15 percent targeted Web servers (HTTP) and domain name services (DNS), which result in site outages and are extremely difficult to mitigate without professional assistance.
  • The average attack during the period reported was 3.5 Gbps, a sustained increase in bit volume, and 0.99 million packets per second (Mpps), a continued decrease in packet volume since last quarter. This indicated a change of attack methods from large volumetric network-based attacks to complex attacks using multiple vectors, with both application layer attacks and SYN flood attacks blended together, meaning security practitioners will need to leverage intelligent DDoS mitigation rather than budgeting extra network bandwidth.
“DDoS attacks continue to fall in size and frequency in 2014, making them easier to handle for tier one carrier networks with excess capacity, but still tricky to manage for organizations with less bandwidth,” said Shawn Marck, co-founder and chief security officer of Black Lotus. “The widespread education of ways to thwart NTP caused attackers to resort to tried and true blends of SYN flood and application layer attacks, which are very difficult to mitigate using conventional network hardware as these types target the same port needed to serve legitimate users.”
Download the full Black Lotus Q3 2014 Threat Report for more details.
About Black Lotus Communications
Black Lotus Communications is a security innovator that pioneered the first commercially viable DDoS mitigation solutions. These advanced solutions enhance the security posture of small and medium businesses and enterprise clients while reducing capital expenditures, managing risk, ensuring compliance, and improving earnings and retention. Breakthrough developments at Black Lotus include the world's first DDoS-protected hosting network, the first IPv6 DDoS mitigation environment, and the first highly effective Layer 7 attack mitigation strategy. For more information, visit www.blacklotus.net or follow Black Lotus on Twitter at https://twitter.com/ddosprotection.

Contacts

Metis Communications
Justine Boucher, 617-236-0500
blacklotus@metiscomm.com

Black Lotus Threat Report Reveals Vietnam, India, Indonesia will Grow Mobile DDoS Attacks in 2015

By Unknown → Tuesday, November 18, 2014
Service providers, carriers must strengthen security to protect operations during next 12 to 18 months 

SAN FRANCISCO – April 22, 2014 – While the network time protocol (NTP) DrDoS threats that became prevalent in early 2014 have been contained, new distributed reflected denial of service threats will lead to attacks in excess of 800 Gbps during the next 12 to 18 months. That prediction is according to the “Q1 2014 Threat Report” issued today by Black Lotus, a leader in availability security and provider of distributed denial of service (DDoS) protection. Black Lotus compiles its quarterly threat reports by drawing on data from  its network logs and analyzing the results for trends in attack size, duration, method, source and other characteristics.

Black Lotus Threat Report - Volume I - Issue 3 - 21 April 2014

The threat report, which covers DDoS attack data between January 1 and March 31, 2014, shows that service providers have been heavily impacted by security threats, including SQL injection attacks, NTP DrDoS attacks, and most recently the TLS heartbeat vulnerability (“Heartbleed”). All of these threats have had profound effects on the ability of service providers to safely operate and protect their customers.

During the first quarter of 2014, novice attackers used DrDoS methods to bypass the DDoS defenses of well-prepared companies by targeting upstream carriers directly. In January 2014, Black Lotus recorded several incidents in which tier 1 carriers in multiple U.S. regions were saturated due to DrDoS attacks, resulting in packet loss as high as 35 percent to customers that were not even targeted by the attacks. By February, the same carriers were better prepared for attacks that exceeded 400 Gbps, and they were able to stabilize their networks with minimal interruption to downstream customers. Greater awareness of NTP DrDoS is critical, but service providers will have to add protections as attackers grow more sophisticated and attacks become more severe.

The report findings also show that:

  • The largest DDoS attack observed during the report period was on February 10. It was 421 Gbps and 122 millions of packets per second (Mpps)
  • Of the 463,621 observed attacks, Black Lotus regarded 90,313 (19.5 percent) of them as severe, characterized by an extreme traffic levels compared to the target’s typical traffic baseline.
  • The average attack during the period reported was 2.7 Gbps and 1.8 Mpps.
  • During the reporting period, 50.3 percent of severe attacks targeted individual applications, most commonly HTTP servers and domain name services (DNS). Attacks on either application can result in site outages and are difficult to mitigate without professional assistance.

“Historically, service providers have been able to operate without providing substantial security services to customers. That’s no longer viable, as threats proliferate and attackers find new ways to amplify the volume of their efforts,” said Jeffrey Lyon, founder of Black Lotus. “To protect themselves and their customers, service providers must now also become security providers by offering integrated hosting and security services such as DDoS mitigation, intrusion defense, and incident response and remediation.”

Black Lotus Threat Report Predicts New DrDoS Attacks in Excess of 800 Gbps in 2015

By Unknown → Tuesday, April 22, 2014
As predicted in last month's report, distributed reflection denial of service (DrDoS) attacks have continued to increase in size and frequency. During the month of January, Black Lotus observed attacks peaking at 136 Gbps in bit volume. On February 9, 2014 NTP DrDoS attacks scaled dramatically increasing to an extremely impressive, record breaking 421 Gbps.


In the February edition:
  • Distributed reflection denial of service (DrDoS) continues to dominate, with NTP DrDoS representing 40% of all severe attacks 
  • The frequency of DDoS attacks has nearly doubled since January 2014 
  • Forward looking observations into February 2014 DDoS attack data

For more information, please download the full Threat Report:

Threat Report: DDoS attacks more than double in frequency, scale dramatically in size

By Unknown → Sunday, March 2, 2014
Black Lotus is starting off the new year with a major shift in how DDoS attack data is handled, analyzed, and ultimately released to the public. In previous years it has been our policy to selectively release some data to the media but largely keep the trends and metrics that we observe a secret. In the modern age of information security, the recognized convention is to share data in hopes of making the internet a safer place to conduct business. We will release a Threat Report each month with a more comprehensive version released quarterly and annually. In the January edition:

  • Distributed reflection denial of service (DrDoS) is helping attackers launch huge volumetric attacks exceeding 100 Gbps in volume.
  • Attackers are preferring to target infrastructure, finding it easier to inundate routers than to target applications directly.
  • DDoS attacks from mobile devices (mDDoS) makes its first significant appearance in Black Lotus traffic reports.

For more information, please download the full Threat Report:


Threat Report: New trends in DDoS attack sizes, vectors, and targets

By Unknown → Thursday, January 30, 2014
On January 8, 2014 Black Lotus released a Threat Advisory on NTP Reflection Attacks which can allow a DDoS attacker to exploit a vulnerability in ntpd versions prior to 4.2.7p26, allowing the attacker to cause a reflection of malicious traffic with an amplification factor of 58.5. For example, 100 Mbps of spoofed NTP traffic can cause 5.8 Gbps of malicious traffic to strike the spoofed target.

Between January 2 and January 6, 2014 Black Lotus collected data on the highly publicized @DerpTrolling (via Twitter) attacks which were allegedly responsible for outages to Xbox Live, EA, League of Legends, and Blizzard. Black Lotus has measured the attacks at a maximum bit volume of 28 Gbps of UDP/123 (NTP) traffic.
For more information, please download the full Threat Advisory:
Black Lotus Threat Advisory - NTP Reflection Attacks - Jan 8 2014



Threat Advisory: NTP Reflection Attacks

By Unknown → Friday, January 10, 2014