Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

8/14/2019
12:40 PM
50%
50%

Attackers Try to Evade Defenses with Smaller DDoS Floods, Probes

Cybercriminals are initiating more attacks using low-bandwidth techniques, but the tactics expand the gray area between DDoS attacks and popular methods of mass scanning.

Cybercriminals are increasingly targeting corporate networks, websites, and online services with low-bandwidth distributed denial-of-service (DDoS) attacks that exploit weaknesses in application infrastructure to disrupt business, Internet infrastructure firm Neustar stated in an August 14 threat report.

In its "Q2 2019 Cyberthreats & Trends" report, Neustar found that DDoS attacks using less than 5 Gbit/s make up a greater share of packet floods, with more than 75% of all attacks using less than 5 Gbit/s in the second quarter of 2019, up from less than 70% the previous year. The average attack consisted of a 0.99 Gbit/s stream of packets, so small that most companies may not notice the impact, says Michael Kaczmarek, vice president of product for Neustar Security.

"People think DDoS is going away," he says. "They think it is this unsophisticated brute-force attack, but by no means is it gone; it has just morphed."

Overall, DDoS attacks increased by 133%, more than doubling, according to Neustar's report. The trend is a reversal from last year, when security firms had documented a decrease in attacks for most of the year. The average attack also showed greater complexity, with 82% of attacks using two or more different threat vectors.

The different vectors aim to find a vulnerable spot in a company's infrastructure and abuse the weakness, Kaczmarek says.

"The attackers are getting more sophisticated in what they are targeting," he says. "They are going after not the most vulnerably guy, but the most vulnerable component of the infrastructure."

Most companies seem to have a pretty good response to attacks, however, with a quarter initiating DDoS mitigation within a minute and another 62% within five minutes. Only 11% of companies actually take longer than 5 minutes to respond to a DDoS attack.

In addition, companies are likely to detect multivector attacks, with only 14% of firms very unlikely or somewhat unlikely to notice smaller attacks.

Neustar argues in the report, however, that any response aside from "very likely to detect a smaller attack" is a security failure. "Fewer than 3 in 10 organizations are very likely to notice smaller multi vector attacks, suggesting that greater awareness would be beneficial," the company states in the report.

The study raises questions about what exactly can be defined as a distributed denial-of-service attack. The inclusion of much smaller attacks, of which seven in 10 companies are not certain to detect, suggests that DDoS attacks are merging with the standard tactic of scanning for vulnerabilities in security companies' lexicons. (The report appears to use a standard definition of DDoS as an attack that denies service.)

"The basic form and composition of the DDoS traffic may not have changed much, but the ability to precisely target these attacks has evolved markedly," the report states. "DDoS attacks can now be directed at specific services, gateways, applications, and Application Programming Interfaces (API), and as the target becomes smaller, less traffic is required to bring it down."

Most companies would likely, however, detect an interruption of service to some part of their infrastructure. Most of these attacks fall in the area of application-layer attacks, and not just denial of service, according to Kaczmarek, who included both credential-stuffing and SQL injection scans as potential examples.

"It could be the attack is targeting a specific resource that you were not aware of," he says. "It could be a billing app that is out there, or an API that is doing a communication between you and the bank. [Finding these attacks is] going to require a deeper investigation."

The upshot is that attackers are no longer focused on just denying service but on a range of goals that can be accomplished with scans, packet floods, and application attacks. For that reason, Internet infrastructure-security companies have followed suit with defenses.

"It goes back to the idea of what is valuable versus what is vulnerable," Kaczmarek says. "I may not notice these attacks immediately, but in the end, even the smaller ones will have a large impact overall."

Related Content

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/30/2020
'Act of War' Clause Could Nix Cyber Insurance Payouts
Robert Lemos, Contributing Writer,  10/29/2020
6 Ways Passwords Fail Basic Security Tests
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Measure and Reduce Cybersecurity Risk in Your Organization
In this Tech Digest, we examine the difficult practice of measuring cyber-risk that has long been an elusive target for enterprises. Download it today!
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5991
PUBLISHED: 2020-10-30
NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.
CVE-2020-15273
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. The issue affects the following components: Edit feed settings, Edit widget area, Sub site new registration, New category registration. Arbitrary JavaScript may be executed by entering specific characters in the account that can ac...
CVE-2020-15276
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is vulnerable to Cross-Site Scripting. Arbitrary JavaScript may be executed by entering a crafted nickname in blog comments. The issue affects the blog comment component. It is fixed in version 4.4.1.
CVE-2020-15277
PUBLISHED: 2020-10-30
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.
CVE-2020-7373
PUBLISHED: 2020-10-30
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is ...