Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

8/14/2019
12:40 PM
50%
50%

Attackers Try to Evade Defenses with Smaller DDoS Floods, Probes

Cybercriminals are initiating more attacks using low-bandwidth techniques, but the tactics expand the gray area between DDoS attacks and popular methods of mass scanning.

Cybercriminals are increasingly targeting corporate networks, websites, and online services with low-bandwidth distributed denial-of-service (DDoS) attacks that exploit weaknesses in application infrastructure to disrupt business, Internet infrastructure firm Neustar stated in an August 14 threat report.

In its "Q2 2019 Cyberthreats & Trends" report, Neustar found that DDoS attacks using less than 5 Gbit/s make up a greater share of packet floods, with more than 75% of all attacks using less than 5 Gbit/s in the second quarter of 2019, up from less than 70% the previous year. The average attack consisted of a 0.99 Gbit/s stream of packets, so small that most companies may not notice the impact, says Michael Kaczmarek, vice president of product for Neustar Security.

"People think DDoS is going away," he says. "They think it is this unsophisticated brute-force attack, but by no means is it gone; it has just morphed."

Overall, DDoS attacks increased by 133%, more than doubling, according to Neustar's report. The trend is a reversal from last year, when security firms had documented a decrease in attacks for most of the year. The average attack also showed greater complexity, with 82% of attacks using two or more different threat vectors.

The different vectors aim to find a vulnerable spot in a company's infrastructure and abuse the weakness, Kaczmarek says.

"The attackers are getting more sophisticated in what they are targeting," he says. "They are going after not the most vulnerably guy, but the most vulnerable component of the infrastructure."

Most companies seem to have a pretty good response to attacks, however, with a quarter initiating DDoS mitigation within a minute and another 62% within five minutes. Only 11% of companies actually take longer than 5 minutes to respond to a DDoS attack.

In addition, companies are likely to detect multivector attacks, with only 14% of firms very unlikely or somewhat unlikely to notice smaller attacks.

Neustar argues in the report, however, that any response aside from "very likely to detect a smaller attack" is a security failure. "Fewer than 3 in 10 organizations are very likely to notice smaller multi vector attacks, suggesting that greater awareness would be beneficial," the company states in the report.

The study raises questions about what exactly can be defined as a distributed denial-of-service attack. The inclusion of much smaller attacks, of which seven in 10 companies are not certain to detect, suggests that DDoS attacks are merging with the standard tactic of scanning for vulnerabilities in security companies' lexicons. (The report appears to use a standard definition of DDoS as an attack that denies service.)

"The basic form and composition of the DDoS traffic may not have changed much, but the ability to precisely target these attacks has evolved markedly," the report states. "DDoS attacks can now be directed at specific services, gateways, applications, and Application Programming Interfaces (API), and as the target becomes smaller, less traffic is required to bring it down."

Most companies would likely, however, detect an interruption of service to some part of their infrastructure. Most of these attacks fall in the area of application-layer attacks, and not just denial of service, according to Kaczmarek, who included both credential-stuffing and SQL injection scans as potential examples.

"It could be the attack is targeting a specific resource that you were not aware of," he says. "It could be a billing app that is out there, or an API that is doing a communication between you and the bank. [Finding these attacks is] going to require a deeper investigation."

The upshot is that attackers are no longer focused on just denying service but on a range of goals that can be accomplished with scans, packet floods, and application attacks. For that reason, Internet infrastructure-security companies have followed suit with defenses.

"It goes back to the idea of what is valuable versus what is vulnerable," Kaczmarek says. "I may not notice these attacks immediately, but in the end, even the smaller ones will have a large impact overall."

Related Content

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-28476
PUBLISHED: 2021-01-18
All versions of package tornado are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configura...
CVE-2020-28473
PUBLISHED: 2021-01-18
The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with defa...
CVE-2021-25173
PUBLISHED: 2021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).
CVE-2021-25174
PUBLISHED: 2021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists when reading malformed DGN files. It can allow attackers to cause a crash, potentially enabling denial of service (Crash, Exit, or Restart).
CVE-2021-25175
PUBLISHED: 2021-01-18
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart). This is issue 1 of 3.