Showing posts with label botnets. Show all posts
Showing posts with label botnets. Show all posts

Thursday, August 11, 2011

IT security – a priority for African businesses







As Kenya prepares to host the IDC IT Security Roadshow, Kaspersky Lab is proud to be a part of such a thought leading event, as the company aims to stress the importance of proactive security measures that businesses operating in East Africa need to understand and implement today, for future success.
“91% of companies have experienced at least one IT security event from an external source in the last 12 months. This high statistic certainly proves just how crucial corporate IT security is now more than ever. The reality is that cybercriminal activity targeted at the corporate has, and will continue, to grow on a global scale, especially as newer, more innovative technologies evolve and become critical business competitive tools. And with the prediction that East Africa will be a significant contributor to Africa’s forecasted growth of 3.7%² in 2011 – the African continent will continue to boom economically where the business landscape will grow – making businesses operating in African countries an ideal target for cybercriminals,” says Sergey Novikov, Kaspersky Lab Head of EEMEA Research Centre.
In their recently released report, Worldwide Security Products and Services 2011 Top 10 predictions, the IDC drew some interesting conclusions that closely correspond to Kaspersky Lab’s strategy and vision in this regard. Of these, the IDC predicts that consumers and enterprises will continue to grow their spending on Endpoint Security at surprising rates – the reason being obvious – corporate IT security is a necessity! Customers and enterprises are looking  for  an  integrated  approach  that  offers  a  broad  range  of  protection from malicious cyber attacks, accidental  disclosure  of  sensitive  information  (consumer  and  corporate),  usage  by  unauthorised  users  (identity  fraud), and  applications (botnets).
“For many years now, Kaspersky Lab has taken an integrated approach to protection in our product offering and believe that IT Security should be top of mind for all businesses operating within the African continent. Apart from the traditional organisation of DDoS attacks, cybercriminals today have a main focus of targeting corporate servers for stealing corporate data and African businesses are not excluded,” says Novikov.
The IDC further predicts that small and medium enterprises (SMEs) globally will see more targeted attacks against data and resources. Small businesses will see increasing attacks on customer data.  Attempts to take full control of servers, PCs, and storage arrays for botnets, DDoS attacks, spam, phishing, hacktivism, and other uses are also expected to increase.
“With SMEs accounting for an estimated 60%³ of all employment in East Africa, and contributing up to 30% of gross national product, the SME sector in East Africa cannot afford to experience such attacks on their organisations, as the results could be detrimental likely having a ripple effect on the economy,” adds Novikov.
The conference will be taking place at the Hilton Hotel in Nairobi, where Novikov aims to provide insight into the above at the IDC IT Security Roadshow, to ensure that businesses operating within the African landscape are made aware of such threats that exist and take the necessary action required to avoid the impact of these attacks.
“The reality today is that proactive security is a requirement for all businesses, to ensure effective protection against such threats and attacks. Corporate servers are being attacked continuously and should such activity continue to take place, a business could stand to loss everything. Implementing the necessary corporate IT security measures now is the next major step for East African based businesses in effectively protecting enterprises – ensuring success and as such, continued positive growth of the African continent,” concludes Novikov.

Tuesday, May 24, 2011

The Explosion of Cybercrime

 
 
Cybercrime is any crime involving a computer or a network and cybercrime has increased significantly in the past decade. Most organizations value employees that have an understanding of IT security risks, and many organizations require employees to have specific security certifications. This article provides an overview of various types of cyber crime, including cyber extorsion, botnets, morophing malware, and online fraud.
Cybercrime is broadly defined as any crime involving a computer or a network. In the last decade, the amount of cybercrime has grown substantially resulting in significant losses to businesses, and lining the pockets of criminals. This article presents some information about some of the common cybercrime activities and it helps emphasize the value of IT security for any organization.
It also helps to emphasize the value organizations place on employees with IT security awareness. The (ISC)2 CISSP has become one of the top IT security certifications and many organizations seek employees with this certification for both IT jobs and managerial positions. Lower level security certifications such as CompTIA’s Security+ and the (ISC)2 SSCP are also valued by organizations. For example, the U.S. Department of Defense requires anyone with an administrative account to have at least a Security+ certification.

Cyber Extortion

In high-crime areas, extortionists have demanded payments from businesses for “protection.” If the businesses refused, the business was attacked, robbed, employees harassed, and in extreme cases, the business was burned. Of course, the extortionists actually attacked the businesses when the protection money wasn’t paid.
Extortion has made it to the cyber community. Attackers use distributed denial of service (DDoS) attacks to show they can cripple Websites and corporate networks. They then demand protection payments to stop the attacks. Ron Lepofsky wrote in 2006 that the U.S. and FBI receive at least 20 new cases of cyber extortion a month. Blackmailers use various types of denial of service attacks to cripple Websites and corporate networks. They then demand protection payments to restore the service. Extortionists have demanded ransoms of more than 1 million dollars to stop the attacks. Some companies quietly pay. Others attempt to fight back.
A smaller form of cyber extortion is in the form of rogueware, or fake antivirus software. A user visits a Website and sees a popup indicating their system is infected, and encouraging them to download free software to clean their system. After the user downloads and installs the software, the rogueware reports several serious infections, but then states that the free version only scans the system, but won’t clean it. If they want to clean their system, they must pay between $49.95 and $79.95 for the full version. PandaLabs reported in 2008 that criminals were extorting approximately $34 million dollars a month from unsuspecting users. While this is bad enough in itself, the rogueware provides zero protection against actual malware, leaving the user with a false sense of security.
Additionally, many rogueware criminals include additional malware in the rogueware. For example, an added keystroke logger can capture a user’s keystrokes (such as capturing passwords for online banking accounts) and periodically send the data to the criminal. Many versions also include software to convert the computer into a zombie as part of a botnet.

Botnets

Botnets have grown to astronomical proportions over the past few years, and despite some successes, they’re still stealing money from people every day. As an example, NBC reported in 2004 how a small business in Miami was attacked. Specifically, their computer was infected with the CoreFlood virus (used in the COREFLOOD botnet) and someone transferred $90K out of their Bank of America account without their authorization to a bank in Latvia. Before this, the COREFLOOD botnet was primarily known for DDoS attacks.
Other losses from the COREFLOOD botnet include $115K from a real estate company in Michigan, $78K from a law firm in South Carolina, $151K from an investment company in North Carolina. The list goes on and on. Don’t think they’re only attacking businesses though. It’s just that when an individual’s $1,000 in savings is stolen, it isn’t as newsworthy as a loss of tens of thousands of dollars. Still, the loss of $1,000 by an individual can be devastating.
Interestingly, a report in June 2008 by Joe Stewart (Director of Malware Research, Dell SecureWorks) showed this same botnet was still in operation and the bot herders had shifted their activities from DDoS attacks, to full-fledged bank fraud. After all, they found they could get quick paydays with much less effort. At that time, they had infected over 378,000 computers and had at least one database with over 50 Gigabytes of data on hapless users around the world. The botnet had captured keystrokes and recorded bank passwords, credit card data, email passwords, social network passwords, and more.
As of February 2010, this botnet had grown to over 2.3 million infected computers with 1.8 million of the computers in the United States. Thankfully, the U. S. Department of Justice took several steps in April 2011 to take over the botnet’s command and control servers and may have succeeded in shutting this botnet down. We’ll see.
The point is botnets are thriving. Even though experts are shutting down some of the large botnets, it’s like a game of whack-a-mole. They keep popping up. In years past, malware was used to cause damage to systems such as corrupting a hard drive or system files. Today, malware is a tool often used by criminals to steal identities and hard cash from regular people just like you and me.

Morphing Malware

Malware is increasingly difficult to detect, mostly because attackers are constantly developing new methods and strategies. One common method used today is polymorphism. Malicious code within a single virus can be run through a mutation engine to create thousands of different versions of the same virus. While one version may be detected by a malware detection signature, thousands of other mutations may get past this signature until another signature is developed to detect the mutated versions.
At one point, it was recommended that you update your antivirus definitions on a weekly basis. Some experts now suggest you update it hourly. Malware vendors are constantly working on detecting new variants, updating signature files, and publishing them.
It’s also worth noting that all antivirus (AV) software is not created equal. Virus Bulletin publishes a monthly report on the effectiveness of AV products that is quite enlightening. You may think that malware products can consistently detect close to 100 percent of malware in the wild, but that is not the case. For example, this graph shows a wide scattering of products in the 60 percent to 80 percent effectiveness ranges. This equates to a grade somewhere between a B and a D. For me, I don’t want the D student protecting my bank accounts and identity.
It’s also worth pointing out that criminals have discovered the power of malware when used effectively for criminal activities. While malware was previously used to take down systems or networks just for the fun of it, criminals don’t do that today. Instead, criminals use malware to enlist zombies into their huge botnets. These zombies then engage in activities allowing the criminals to steal money from people and organizations on a grand scale.

Zero Day Vulnerabilities

Zero day vulnerabilities are those that are known to attackers, but either not known to the vendor, or the vendor has not developed and released a fix yet. While this implies that a zero day vulnerability lasts only a single day, it can actually last months before a fix is written, tested, and released.
In other words, even if you are taking steps such as keeping a system up-to-date, running AV software, and regularly updating signature files, you are still at risk from zero day vulnerabilities. Defense-in-depth procedures within an organization include a variety of other security practices to protect systems and networks to help protect them from zero day vulnerabilities.

Online Fraud

Cybersource publishes an annual fraud report on online fraud. Online fraud is fraud occurring through the Internet, such as charges on stolen credit cards, and chargebacks required by a credit card’s issuing bank. In the 2011 Online Fraud Report, Cybersource reported that losses from online fraud was about 2.7 billion dollars in 2010.
The good news is that online fraud appears to be declining. Online revenue losses due to fraud were estimated at 3.3 billion in 2009 and a peak of 4 billion in 2008. While this may look like criminals are trying less, that’s not actually the case. Instead online retailers have dedicated more and more resources to blocking cybercrime and are enjoying some success. That is if you want to call an annual loss of 2.7 billion dollars a success.

Conclusion

If you’re studying IT security certifications (such as CompTIA Security+, or the (ISC)2 SSCP or CISSP), expect your skills and your knowledge to be in high demand. Organizations using computers, and especially organizations with an online presence, are recognizing the risks to IT systems and networks. More and more organizations value individuals that understand these risks.

http://www.informit.com/articles/article.aspx?p=1713590

Monday, November 15, 2010

DDoS as a Service......

The IMDDOS botnet is operated out of China and has been growing at the rate of about 10,000 infected machines every day for the past several months, to become one of the largest active botnets.

The site offers various subscription plans and attack options, and provides tips on how the service can be used to launch effective DDoS attacks. It even provides customers with contact information for support and customer service.
Anyone with knowledge of Chinese can essentially subscribe to the service and use it to initiate DDoS attacks against targets of their choice, anywhere around the globe and with next to no effort, Ollman said.
Paid subscribers are provided with a unique alias and a secure access application which they download on to their systems. Users wishing to launch an attack use the application to log into a secure area on the Web site where they can list the hosts and servers they want to attack and submit their request.

Many of the hacking tools and services sold on such sites are inexpensive, highly customizable and designed to be used by novices. Prices for malware tools often start at just $20.
As in the case of the IMDDOS botnet, such sites often offer support services, formal product upgrades, end-user license agreements and tools that let customers verify how effective their attacks really are.


http://news.techworld.com/security/3239473/damballa-warns-of-fast-growing-botnet/

Saturday, November 6, 2010

First Jail Sentence For Romanian BitTorrent Site Operator





The owner of a Romanian BitTorrent tracker has been the first person in the country to receive a jail sentence for his actions. Following complaints from the Business Software Alliance, Kartel.ro was closed in 2007 but it has taken three years for the case to come to a conclusion. The outcome is a 6 month suspended sentence and an unspecified fine.
The Romanian division of the Business Software Alliance has been trumpeting various successes from its work cracking down on the use of unauthorized software.

http://torrentfreak.com/first-jail-sentence-for-romanian-bittorrent-site-operator-101104/

Former Student Gets 30 Months in Prison for DDoSing Conservative Figures and Using Botnets






Mitchell L. Frost, age 23, of Bellevue, Ohio a former University of Akron student was sentenced Friday to 30 months in prison, followed by 3 years of supervised release for conducting Denial of Service Attacks on the sites of several prominent conservative figures as well as infecting several systems with botnet zombies.


The former student also admitted initiating denial of service attacks against University of Akron computer servers on or about March 14, 2007, which caused the entire University of Akron computer network to be knocked off-line for approximately 8 1⁄2 hours, preventing all students, faculty and staff members from accessing the network. The University claimed that response and remediation efforts to restore network services cost over $10,000. 



Friday, November 5, 2010

DDoS attacks by agentless botnets







 Interesting article on http protocol flaws that could result in DDoS attacks by agentless botnets: 


 A flaw in the HTTP protocol leaves the door open for attackers to wage a new form of distributed denial-of-service (DDoS) attack that floods Web servers with very slow HTTP "POST" traffic.

http://www.darkreading.com/vulnerability_management/security/attacks/showArticle.jhtml?articleID=228000532