The Evolving Threat of DDoS Attacks
Jan 01, 0001
Jan 01, 0001
What CFEs and their organizations should know about zombie armies and robot networks.
What CFEs and their organizations should know about zombie armies and robot networks
January 2013
By Zach Capers, CFE
As the 2012 holiday season was wrapping up, several major
banks including Wells Fargo, PNC and Bank of America were busy defending their
websites against online distributed denial of service (DDoS) attacks. For
several weeks, the assailants, known as the Izz-ad-Din al-Quassam Cyber
Fighters, have been bombarding U.S. online banking sites with data in an effort
to knock them offline and prevent legitimate customers from accessing their
accounts. The group has promised to continue the DDoS attacks until an incendiary
video that was recently posted online is removed from the Internet.
Perhaps the most prominent DDoS attacks have been executed by the infamous hacker collective known as Anonymous. In recent years, the group has conducted several high profile DDoS attacks on financial institutions, web-hosting companies and government websites. Anonymous uses the attacks to draw publicity to their causes such as perceived injustices and censorship. While the DDoS attacks by Anonymous appear to be strictly political in nature, cybercriminals might use DDoS attacks for other purposes, including the commission of fraud.
Motivations for DDoS Attacks
Ideology – The most commonly recognized motivations for DDoS attacks are spawned by political fervor. Ideological hackers, or hacktivists, often target government agencies and companies involved in controversial industries. In late 2010, several credit card companies were temporarily taken offline by DDoS attacks launched by groups sympathetic to WikiLeaks, which had just had its credit services suspended.
Extortion – Companies might receive a demand for payment in order to avoid having their websites knocked offline by DDoS attacks. A similar tactic is the increasingly pervasive use of ransom-ware, which infects a computer, locks it and displays a message threatening that the user’s files will be deleted if a payment is not received.
Competition – DDoS attacks might be carried out in order to disrupt a competing organization’s online services. These attacks can inflict significant damage to the reputation and finances of companies that primarily conduct their business online.
Fraud – DDoS attacks are now being used as a tool to aid in fraud. While an organization’s technical personnel are distracted by a DDoS attack, fraudsters might simultaneously attempt to access customer accounts and other sensitive information. In December of 2012, the U.S. Office of the Comptroller of the Currency issued an alert detailing the connection between fraud and DDoS attacks on financial institutions.
What Are DDoS Attacks?
A typical DDoS attack consists of a hacker using a master computer to infect and control thousands of compromised "zombie" computers around the world to flood a target server with data. As Web servers are only able to handle so much information at any given time, if one is overloaded, it might be disabled or disrupted, thus resulting in a denial of service to a website’s intended users. DDoS attacks have now advanced into much more powerful and insidious varieties, such as DNS amplification attacks and application layer attacks, both of which are far more powerful than traditional DDoS attacks. Due to the dispersed nature of the onslaughts, purveyors of this computerized mayhem are notoriously difficult to identify or deter.
The weapon used by hackers to launch a DDoS attack is known as a botnet, which is short for robot network. Botnets, also known as zombie armies, are composed of countless compromised computer systems and servers which are exploited by hackers for various uses, including the distribution of spam, phishing and denial of service attacks. The zombified computers are usually infected by malicious software (malware) that is unknowingly installed by users via links in spam, weaknesses in software or hazardous websites. Botnets are quite profitable, as their operators often rent their networks to others who wish to bring down websites.
Voluntary Botnets
While a large proportion of host computers used by botnets in DDoS attacks have been overtaken by malware unbeknownst to their owners, other machines are submitted by their owners voluntarily to contribute to the hackers’ cause. A simple-to-operate and widely available software program, known as Low Orbit Ion Cannon, may be downloaded to any computer in order to transform the machine into a weapon for denial of service attacks. The program has been a favorite of Anonymous, and of those sympathetic to their cause. Due to the secrecy of the group’s membership, one way for followers of Anonymous to show their support is by downloading the software in order to provide further means for DDoS attacks. During the last year, an updated and much more powerful version of the program, known as High Orbit Ion Cannon, has been proliferating on the Web.
Federal Crackdown Against Botnets
The U.S. government has scaled up its efforts to crack down on botnet operators. The U.S. Justice Department recently announced the arrest of 10 people from seven different countries who are accused of running an international botnet ring responsible for infecting more than 11 million computers and causing $850 million in financial losses. The botnet, known as Butterfly, was designed to steal banking information, and was spread by a virus that primarily targeted Facebook users, as well as users of instant messenger services such as AIM and Yahoo! Messenger.
Mobile Devices Under Attack
The proliferation of mobile devices offers cybercriminals a new means to carry out DDoS attacks. As was the case in 2012, a rapid increase in the volume of mobile malware is expected to continue in 2013. As consumers increasingly rely on their smartphones and tablets, cybercriminals are accordingly targeting these devices with malicious code, often in the form of Trojans that mimic valid apps. Mobile malware is being used to steal personal information such as bank account passwords, to force access to premium services, and increasingly to create botnets for use in DDoS attacks.
DDoS Attack Prevention for Individuals
Certified Fraud Examiners should be aware of the methods used by cybercriminals to commit crime and how to avert it. A few simple ways to prevent a computer or device from being infected by malware, which might enable its use in a botnet, include:
Operating systems, browsers, apps, and all other software should be kept up to date. Maintaining the latest version of often exploited software such as Java and Adobe Flash Player is critical for the protection of a machine.
A trusted antivirus program should be used and kept current. Scans should be scheduled to run once a week. Mobile antivirus software and apps such as Lookout are also available.
Always use a firewall.
The practice of jailbreaking a device should be avoided as the process leaves that device wide open to malware.
When downloading software from the Internet, close attention should be paid to check boxes during the installation process, and the user agreement should be read completely before proceeding.
When downloading apps, the provider’s reputation should be verified. Furthermore, apps should not request excessive permissions beyond the scope of their intended use.
Caution should be used when clicking links on social networking sites or banner ads throughout the Internet. Malicious code is often built into seemingly innocuous links and ads, some of which might even appear on well-known websites.
DDoS Attack Prevention for Organizations
DDoS attacks are constantly evolving and their mitigation is an ongoing struggle for many organizations. There are several ways to reduce an organization’s chances of falling victim to these attacks, including:
As the goal of a DDoS attack is to overwhelm your organization’s servers, ensure that you have an excess of bandwidth available and the ability to balance large volumes of Web traffic.
Set up strong firewalls and disallow all unnecessary network traffic.
Ensure that your domain name service (DNS) server is protected from attack. A DNS server maintains Internet domain names, IP addresses and other critical software necessary for allowing your website to be accessed.
Have a response plan ready to implement quickly in the event of an attack.
Consider using a DDoS mitigation or filtering service. An entire industry has sprung up in recent years offering to detect and absorb DDoS attacks.
All victims of cybercrime are encouraged by the FBI to file a complaint at www.ic3.gov, or contact their local FBI field office, www.fbi.gov/contact-us/field/field-offices.
Conclusion
Modern DDoS attacks are a progression of the formerly common "ping of death" attack which sought to confuse network systems by sending indecipherable information. What started as vandalism for notoriety in the hacker community has morphed into a powerful tool for Internet activists, cybercriminals, and fraudsters. As we enter a new year, there is little doubt that the challenges presented by botnets and DDoS attacks will continue to increase in number and complexity in 2013. Awareness and preparation are key to protecting individuals and organizations from victimization by cyber-attacks.