Arbor Networks: Targeted DDoS Attacks, Mobile Security Gaps
Denial-of-Service attacks pose a serious risk to business continuity, but enterprises are increasingly relying on ISP and third-party service providers to mitigate the threat, according to a study released Tuesday by Arbor Networks.
The Burlington, Mass.-based company's eighth annual Worldwide Infrastructure Security Report found Distributed Denial-of-Service (DDoS) attacks are increasingly being tied to targeted malware attacks in an attempt to infiltrate businesses.
The report surveyed 130 network security operations engineers, analysts and other executives and management involved with enterprise and network operations in a mixture of Tier 1, Tier 2 and Tier 3 networks from October 2011 through September 2012.
[Related: New Threats Of Cyberattacks Against U.S. Banks ]
An increasing number of people are becoming alarmed that DoS attacks are being carried out in conjunction with attacks attempting to steal account credentials, intellectual property and other sensitive data, according to the Arbor Networks report. Those surveyed said the BYOD craze has resulted in less visibility into networks and more entry points into corporate systems. Approximately 40 percent of those surveyed have the means to monitor the use of smartphones and mobile devices, the survey found.
The Arbor Networks study illustrates the surge in media attention being paid to DoS attacks on large businesses in recent months, fueled in part by hacktivist groups and others attempting to disrupt business operations. Operation Ababil, tied to Iranian cyberattackers, has been targeting large U.S. banks.
According to Arbor Networks, the strength of DDoS attacks has not increased over the past three years but the tactics have changed.
"Technology isn't really evolving that fast in terms of the technology and tools being used, but we are seeing sophistication in how they are combined with other methods of attacks," said Gary Sockrider, solutions architect for the Americas at Arbor Networks. "Attackers are going to do whatever it takes to bring sites down and, with a trend toward multivector attacks, you don't need a volumetric brute force attack to bring sites down."
NEXT: The Growing Threat Of Multivector Attacks
The Arbor survey found multivector attacks involving more than a flood of network packets is making DDoS mitigation increasingly tricky. Banks and other companies that depend on websites or Web portals for their business are taking a layered approach to handle the onslaught of traffic, contracting out to an ISP for mitigation services and additional third-party service providers to help filter traffic.
Multivector attacks are up 27 percent from 2011, driven by the fact that the automated tools used for DDoS frequently now contain additional capabilities. Application-layer attacks targeting Web services were reported by 86 percent of those surveyed. Attackers are also able to target encrypted communication services as well.
Data centers also are increasingly being targeted, with nearly 50 percent of those surveyed experiencing DDoS attacks aimed at their data centers, resulting in operational expenses as a result of a disruption in business.
PUBLISHED JAN. 29, 2013