Black Lotus delivers award winning DDoS protection ranging from full network defense to website and server protection, 24/7/365. Learn more by visiting http://www.blacklotus.net or call (866) 477-5554.

Browsing "Older Posts"

Browsing Category "cyber security"
Have you ever been the victim of a pickpocket? They often work in pairs, with one crook distracting you with conversation while the other relieves you of your wallet. Some cyber criminals are now using DDoS attacks to perpetrate “cyber pickpocketing” on a massive scale.
DDoS Attacks As Distractions
Think about what happens when you become the victim of a DDoS attack. Phones ring off the proverbial hook, customers complain about the breakdown in service, users panic, etc. – all while you’re trying to detect the source, stop the attack, and get your systems back up and running. Can you imagine a better distraction? Cyber criminals have already come to that realization, which is why they’re now using DDoS attacks to camouflage more sinister breaches. The next time your company experiences a DDoS attack, you may want to make sure it’s not just a smokescreen for the real crime.
How It Works
Unlike typical DDoS attacks, which often consume the network’s entire bandwidth, these distraction attacks leave just enough bandwidth open for hackers to accomplish their true purpose. Hackers count on everyone being so busy with the DDoS attack that they don’t notice the breach – or, if they do, they put it on the back burner until the DDoS attack is resolved. In the meantime, the hackers are busy extracting data, installing malware, or carrying out some other type of mischief. In addition, during traffic surges, some security protocols default to open in an attempt to keep things up and running. This creates the perfect opportunity for hackers to access just about anything they want.
In a variation of that scheme, some hackers use DDoS attacks to probe for system vulnerabilities. In this case, the DDoS acts as a Trojan horse, with the real threat going undetected. In 2013, attackers used this technique to steal $1 million in bitcoins from Danish payment processor BIPS.
Best practices
With the increase in “DDoS as distraction” attacks, your best bet is to avoid putting all of your IT resources into stopping the attack. Instead, assume that it might be a smokescreen for other illegal activity. Hold a team back and task them with monitoring the network for anything unusual. And, once you’ve successfully mitigated the DDoS attack, give your system a thorough checkup to make sure everything is in order.

No company is too big, too small, or too obscure to be the victim of a DDoS attack, whether it’s carried out as a nuisance or as camouflage for something else. Due to the many moving parts involved in data security, as well as the constantly evolving sophistication of hackers, many companies are deciding to outsource at least some parts of their data security to experts. And even the experts tend to specialize, with some focusing only on things like DDoS detection and mitigation. Whether you outsource your security or take care of things in-house, it’s critical to have detailed plans in place for both prevention and response. How confident are you in your network’s security?

DDoS Attacks: The New Trojan Horse

By Unknown → Monday, March 23, 2015
“Hacktivism” is going mainstream, and DDoS attacks are becoming the weapon of choice. They’re inexpensive and fairly easy to carry out, especially if you take advantage of some of the “DDoS as a service” options that are out there. A DDoS attack takes a lot less effort than carrying a sign and rallying outside of a business’s headquarters, and it delivers a far bigger punch than the inconvenience of a protest. As a result, companies are going to need DDoS response plans, and those plans are going to have to cover more than just the technical aspects.

The BBC “attack”
The BBC provides an interesting example. The BBC recently suspended Jeremy Clarkson, host of the wildly popular Top Gear series. The suspension happened after Clarkson allegedly punched one of the producers, and it left the last three episodes of the season in question. Fans were outraged, and the hacktivist group Anonymous sent an open letter to the BBC in which they threatened to launch a DDoS attack if the BBC didn’t reinstate Clarkson. The letter read, in part, “You don’t want to piss of 300 million viewers. You are warned: DDoS cannons will fire if you don’t comply.”

A few days later, the BBC website went down. Despite the timing, the BBC says that the outage was due to an internal server problem rather than a DDoS attack.

The PR angle
We may never know whether the BBC outage was really due to a DDoS attack, but the BBC’s response raises some interesting questions. Why would an organization deny that it had been a victim of an attack? There are actually several reasons they might want to keep that quiet. For one thing, company executives might worry that customers will start thinking their information is at risk, or that the company’s services are unreliable. They might worry that publicly admitting their vulnerability would invite more attacks. Public companies might fear a drop in stock price. But there are other issues at play, too.

Hactivists tend to have a lot of popular support, and some organizations have experienced backlash after taking legal action against the hackers. On the other hand, not taking any action could invite more attacks. So executives might think it’s easier to just make the problem go away. And then there’s the whole extortion angle. If you give into hacktivists’ demands, even once, you’re opening the floodgates for more of the same. Labeling it an “internal server problem” might be the easiest solution, from a PR angle.


Whether or not the BBC outage was the result of a DDoS attack isn’t really the point, however. The point is that everybody is vulnerable. Even if your company is in the unlikely position of never having offended a single person, you’re still not safe from attackers who assail businesses because they’re bored—or just to prove they can. What systems does your company have in place to defend against DDoS attacks? How long would it take you to notice an attack was underway? How would you stop it? And what would your public response be? If you don’t know the answers to those questions, you need to find out, and you need to do it today.

DDoS Attacks Are More Than Just a Technical Problem

By Unknown → Friday, March 20, 2015
Looking at how much technology has changed our world over the years – even just over the past decade – can take your breath away. But, while the speed of incremental change is constantly accelerating, drastic overnight change is far less common. It still happens, however, and the Sony breach is one recent example. When that news hit, IT security professionals all over the world were slapped in the face with the reality of business disruption attacks, which can cripple an organization’s internal networks to the point where its employees can’t do business. The result was a wakeup call that initiated a shift from a “defend and detect” mode to “detect and respond”.
Cyber security as part of disaster management
What does this shift imply? For one thing, it means that more and more businesses will formulate documented responses to cyber attacks. Shawn Marck, CSO of cyber security firm Black Lotus, predicts, “Cyber security response will become a basic element of disaster and business continuity planning. What will you do if all of your emails and financial records are suddenly gone? What will be your PR response if negative information is stolen and exposed? What are your plans for retaining customers if your business is down for days at a time? If those customers leave, what will you do to get them back? And what support will you offer customers whose personal data is stolen? Companies that have a documented response plan will be at a distinct advantage over those that have to come up with it in the middle of a crisis.” Backing up what Marck says, research firm Gartner recently released a report saying that, by 2018, 40 percent of companies will have a formal plan in place for responding to cyber attacks, up from zero percent just a few years ago.
Shift toward detection and response
But disaster preparedness is just one piece of the puzzle. IT security professionals also need to have a plan in place for detecting an attack as soon as it begins and for stopping it before irreversible damage is done. Gartner vice president Paul Proctor says, “Entirely avoiding a compromise in a large, complex organization is just not possible, so a new emphasis toward detect and respond approaches has been building for several years, as attack patterns and overwhelming evidence support that a compromise will occur.” That brings cyber attack detection and mitigation to the top of the priority list for IT professionals in companies of all sizes.

Marck explains, “Standard detection strategies like pre-defined traffic patterns aren’t enough anymore, especially against the rising threat of application-layer attacks. Both detection and response strategies are becoming increasingly complex as these attacks become more sophisticated.”

In fact, many companies are choosing to outsource attack detection and mitigation. Some companies just don’t have the skills or resources to handle such a mission-critical project in-house. Others recognize the benefit of partnering with specialists who are plugged into that world and always up-to-date on the latest developments and attack methods. Regardless of whether you outsource your cyber security or do it in-house, it’s something that no business can afford to ignore.

The Next Evolution of Cybersecurity

By Unknown → Tuesday, March 17, 2015