Report shows most DDoS attacks in Q3 2018 targeted communications service providers.
TELECOMWORLDWIRE-January 28, 2019-Report shows most DDoS attacks in Q3 2018 targeted communications service providers
(C)1994-2019 M2 COMMUNICATIONS http://www.m2.com
The Nexusguard "Q3 2018 Threat Report" has revealed the emergence of an extremely stealthy distributed denial-of-service (DDoS) attack pattern targeting communications service providers (CSPs), the company said.
This new vector exploits the large attack surface of ASN-level (autonomous system number) CSPs by spreading tiny attack traffic across hundreds of IP (Internet protocol) addresses to evade detection. The ongoing evolution of DDoS methods suggests that CSPs need to enhance their network security posture and find more effective ways to protect their critical infrastructure and tenants. The continued discovery of new attack patterns should also alert enterprises to the importance of selecting DDoS-proof service providers.
The quarterly report, which measures thousands of DDoS attacks around the world, showed communications service providers were targeted by 65.5 percent of DDoS attacks in Q3, given their extensive networks enabling access to tenants' assets.
Attackers were found to have contaminated a diverse pool of IP addresses across hundreds of IP prefixes (at least 527 Class C networks, according to Nexusguard findings) with very small-sized junk traffic. As a result, the year-over-year average attack size in the quarter fell measurably - 82 percent.
Nexusguard analysts believe that attackers conducted reconnaissance missions to map out the network landscape and identify the mission-critical IP ranges of targeted CSPs. Then they injected bits and pieces of junk into legitimate traffic, whose size easily bypassed detection thresholds. Mitigating broadly distributed, small-sized attack traffic is more difficult at the CSP level, in comparison to the traditional volumetric attack method on a small number of targeted IPs.
The convergence of polluted traffic that slips through the "clean pipes" of upstream Internet service providers forms a massive traffic flow that easily exceeds the capacity of mitigation devices, to high latency at best, deadlock at worst.
The "bit-and-piece" attacks observed in the quarter often leveraged open domain name system (DNS) resolvers to launch what is commonly known as DNS Amplification, whereby a targeted IP address receives only a small number of responses in each well-organized campaign, leaving little or no trace. Black-holing all traffic to an entire IP prefix may be costly since black-holing will also block access to a wide range of legitimate services.
Founded in 2008, Nexusguard is a cloud-based distributed denial of service (DDoS) security solution provider fighting malicious Internet attacks. Visit www.nexusguard.com for more information.
((Comments on this story may be sent to firstname.lastname@example.org))
|Printer friendly Cite/link Email Feedback|
|Title Annotation:||distributed denial-of-service|
|Comment:||Report shows most DDoS attacks in Q3 2018 targeted communications service providers.(distributed denial-of-service)|
|Date:||Jan 28, 2019|
|Previous Article:||XY - The Persistent Company adds to global advisory board.|
|Next Article:||DataGryd plans MegaSuite 6.|