WEB THREATS, SECURITY, and Ddos Due to the Constantly Changing Threat Landscape, Keeping Corporate Networks Secure Is Particularly Tricky These Days
Total Page:16
File Type:pdf, Size:1020Kb
Sponsored by WEB THREATS, SECURITY, AND DDoS Due to the constantly changing threat landscape, keeping corporate networks secure is particularly tricky these days. Threats continue to increase and evolve as attackers attempt to stay one step ahead of their targets, employing new technology, social engineering scams, and the element of surprise. Distributed Denial-of-Service (DDoS) attacks continue to plague organizations, while newer strategies such as advanced persistent threats (APTs) and spear phishing are becoming more common. In these articles, Network World and its sister publications CSO, CIO, InfoWorld, and Computerworld offer news, advice, and commentary on securing modern enterprise IT environments. IN THIS eGUIDE 2 What it’s like 4 Ponemon 5 PayPal CISO: 8 The Internet 10 Spear 12 The DDoS 14 Phishing still 16 Internet to get hit with a study: Cyber DDoS one big needs its own phishers sharpen Hall of Shame rules, because Security DDoS attack attacks more security threat Weather Channel skills, craft ‘in- Distributed denial- we’re still gullible Resources Akamai often finds frequent, severe among many An Internet early- credible’ attacks, of-service attacks Despite more than a Additional tools, tips itself scrambling to Most respondents say PayPal CISO Michael warning system would says experts like those against decade of warnings, and documentation to WordPress now part stop a DDoS attack they expect to be hit Barrett also urges help organizations stay But rash of targeted users still readily fall help guide you through of the political against one or more of again this year other security pros a step ahead of cyber attacks may also mean for phishing attacks the maze of Internet guerilla’s toolkit its clients to advise Congress criminals more companies com- malice on Internet security ing clean legislation Hit with a Cyberattacks more DDoS one security Internet needs its own Spear phishers DDoS Hall Phishing Resources DDoS Attack frequent, severe threat of many Weather Channel sharpen skills of Shame still rules WEB THREATS, SECURITY, AND DDoS Sponsored by WHAT IT’S LIKE TO GET HIT WITH A DDoS ATTACK Bill Brenner • CSO Transportation. U.S. Bancorp, the nation’s sixth-largest Akamai often finds itself scrambling to stop a DDoS attack commercial bank, also took a direct hit. Attackers have also targeted the likes of Amazon, Google and Yahoo. At- against one or more of its clients tacks against Google didn’t last long, but when one con- siders that Google content accounts for about 5 percent Google. Twitter. Government websites. Fortune 500 compa- So what’s it like to be in charge of this much computing of all Internet traffic, the prospect of better-sustained at- nies. All have been victims of crippling distributed denial-of- power when the attacker decides to strike? Akamai Secu- tacks against it is sobering. service (DDoS) attacks. The attacks have grown in reach and rity Evangelist Michael Smith recently took an audience When a DDoS is underway, Smith said, customers pan- intensity thanks to botnets and a bounty of application flaws. at the SecTor security conference through a blow-by-blow ic some, but it’s not the freak-out you might expect. And Akamai Technologies has a seen it all firsthand. account of some recent high-profile cases. “There is a bit of panic if the traffic starts hitting your Many people use Akamai services without even realiz- Taking center stage is the massive cyberattack on gov- infrastructure because things start failing over. So you’re ing it. The company runs a global platform with thousands ernment websites and others around the world during the doing the usual ‘restore service’ drill, but it’s going in mul- of servers that customers rely on to do business online. Fourth of July long weekend in 2009. In that onslaught, a tiple directions, and then it seems like all of your infra- The company currently handles tens of billions of daily botnet of some 180,000 hijacked computers hammered structure is in a cascade failure,” he said. “Maybe a better Web interactions for such companies as Audi, Fujitsu and U.S. government websites and caused headaches for way to describe it is that you’re scrambling to fix stuff and NBC, and organizations like the Department of Defense businesses here and in South Korea. you don’t really have time to panic.” and Nasdaq. There’s rarely a moment—if there are any— The attack started that Saturday, knocking out websites Even in an Akamai environment, if the attackers target dy- when an Akamai customer is not under the DDoS gun. for the Federal Trade Commission and the Department of namic content—which is set to not cache—that goes through 2 of 16 Hit with a Cyberattacks more DDoS one security Internet needs its own Spear phishers DDoS Hall Phishing Resources DDoS Attack frequent, severe threat of many Weather Channel sharpen skills of Shame still rules WEB THREATS, SECURITY, AND DDoS Sponsored by Akamai back to your origin, you’ll see a traffic spike with your every 3 milliseconds like you might think,” he says. “There has to be some panic, but then you calm down servers, Smith said. “Obviously we have ways to respond af- And some people don’t panic because they may have and realize it’s manageable because you have time to re- ter that by caching the dynamic traffic for a small amount been warned of the attack. If you’re the target of an activ- act,” Smith says. “But during the first 30 minutes of the of seconds—most dynamic content is actually cacheable for ist or protester attack, you might hear about it beforehand attack, you’re still sitting with your fingers crossed watch- a small period of time because the browser isn’t loading it as they make plans via online forums. ing to see if anything gets through your defenses.”• 3 of 16 Hit with a Cyberattacks more DDoS one security Internet needs its own Spear phishers DDoS Hall Phishing Resources DDoS Attack frequent, severe threat of many Weather Channel sharpen skills of Shame still rules WEB THREATS, SECURITY, AND DDoS Sponsored by PONEMON STUDY: CYBER ATTACKS MORE FREQUENT, SEVERE Tim Greene • Network World more than that, and 16% saying they couldn’t determine Most respondents say they expect to be hit again this year what their breaches cost. Most of the incursions took place on mobile devices Cyber attacks are becoming more frequent and severe, Given these numbers, 53% have low confidence that (28%) or on devices owned by business partners (27%). and the vast majority of businesses have suffered at their networks would avoid attacks in the next year; 24% Another 20% took place in corporate branch offices and least one data breach in the past year, a Ponemon Insti- say they have high confidence they won’t suffer attacks, 16% at headquarters. tute survey says. the survey says. A third (34%) have low confidence their Of those companies that did suffer attacks, 40% don’t According to the survey, 77% of respondents say network infrastructure can protect against attacks. know where the attacks came from. The top three causes attacks have been more severe or more difficult to “We believe the fact that so many organizations are of security breaches are insider abuse, malicious soft- prevent over the past 12 to 18 months, while 78% say having multiple breaches is resulting in a low opinion ware downloads and malware from a Web site. attacks are more frequent. The survey was sponsored about security preparedness and a low level of confidence Employee laptops were the most common (34%) end- by Juniper Networks. they have to prevent a future attack,” the survey says. point from which security breaches occurred followed by Only 10% of those who answered the survey say they The cost of 55% of the breaches was between mobile devices such as tablets and smartphones (29%) had no data breaches and 53% say they had one to three. $250,000 and $1 million, with 19% saying the cost was and corporate desktops (28%). • 4 of 16 Hit with a Cyberattacks more DDoS one security Internet needs its own Spear phishers DDoS Hall Phishing Resources DDoS Attack frequent, severe threat of many Weather Channel sharpen skills of Shame still rules WEB THREATS, SECURITY, AND DDoS Sponsored by PAYPAL CISO: DDoS ONE BIG SECURITY THREAT AMONG MANY Tim Greene • Network World ing, but we haven’t figured out how,” Barrett says. “You PayPal CISO Michael Barrett also urges other security pros to advise can’t shut off the Internet for a significant length of time.” Congress on Internet security legislation As for APTs, Barrett says they pose two big problems: how to detect them since they are typically hard to find with signature-based tools, and what to do about them Stung by a high-profile denial-of-service attack in Decem- curity. In addition, he says that the payment card indus- when they are found. APT code is designed to burrow into ber, PayPal’s CISO says application layer attacks remain a try (PCI) standards for protecting credit card information networks and resist eradication so even if one instance is major threat to businesses in general, which need better need some tweaking to give businesses more flexibility discovered and cleaned, others remain to carry out mali- defenses and actual testing of the DDoS tools they have. without hurting security. cious activity, he says. “We need better planning as an industry,” says Michael But as for DDoS attacks, businesses need to plan de- A piece of malware found on a PC, for example, could Barrett, the CISO of PayPal, whose blog site was knocked of- fenses and confirm how well they will handle real attacks be a simple virus infecting one machine or it could be fline late last year by the political hacking group Anonymous.