<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blog Central &#187; distributed denial of service</title>
	<atom:link href="http://blogs.mcafee.com/tag/distributed-denial-of-service/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com</link>
	<description></description>
	<lastBuildDate>Fri, 24 May 2013 19:54:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Combating Distributed Denial of Service Attacks in Brazil, Latin America, and Everywhere Else</title>
		<link>http://blogs.mcafee.com/mcafee-labs/combating-distributed-denial-of-service-attacks-in-brazil-ltam-and-everywhere-else</link>
		<comments>http://blogs.mcafee.com/mcafee-labs/combating-distributed-denial-of-service-attacks-in-brazil-ltam-and-everywhere-else#comments</comments>
		<pubDate>Thu, 03 Nov 2011 23:34:23 +0000</pubDate>
		<dc:creator>David Marcus</dc:creator>
				<category><![CDATA[McAfee Labs]]></category>
		<category><![CDATA[Brazil]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[distributed denial of service]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[LOIC]]></category>
		<category><![CDATA[SlowLoris]]></category>

		<guid isPermaLink="false">http://blogs.mcafee.com/?p=12313</guid>
		<description><![CDATA[One of the most disruptive attacks to deal with in today&#8217;s threat landscape is the distributed denial of service attack, often called DDoS. Using the resources of many other computers, an attacker can focus a vast amount of packets and power at a single resource and effectively knock it offline for as long a time <a href="http://blogs.mcafee.com/mcafee-labs/combating-distributed-denial-of-service-attacks-in-brazil-ltam-and-everywhere-else">Read more...</a>]]></description>
				<content:encoded><![CDATA[<p>One of the most disruptive attacks to deal with in today&#8217;s threat landscape is the distributed denial of service attack, often called DDoS. Using the resources of many other computers, an attacker can focus a vast amount of packets and power at a single resource and effectively knock it offline for as long a time as desired. This is a class of attack that must be respected and properly prepared for.</p>
<p>Recently McAfee Labs became aware of a series of the DDoS attacks taking place in Brazil during the last several days. Victims of these attacks included those in the telecommunications and banking sectors. Upon analysis, these attacks appear to use a mix of attack techniques: old-school SYN and ICMP flooding, while at the same time newer tools such as LOIC and SlowLoris. Regardless of the tools used, these types of attacks can be devastating to an online business and its brand.</p>
<p>While the attacks on Brazilian companies do not stand out in their technique (good DDoS is still DDoS), they are significant because Brazil is a large, fast-growing economy that affects other regions and should be looked at in a serious light regardless of the attackers and their motivations. So the question remains: What strategies can companies use to minimize the damage from these types of attacks?</p>
<p>No one technology will do the job. Never has, never will. Good security is about process, people, and technology. Certainly newer technologies like next-generation intrusion prevention and firewalls with IP reputation are of great value and should be looked at; but a good, thorough penetration test should be at the top of everyone&#8217;s list along with forensics and a good incident-response plan.</p>
<p>If your company is in the same business as some of the recent victims, then this is a good time to take stock, undergo a good pen-test, and see how well prepared you are.</p>
<p>Revisit your security basics, layer your defenses, and <strong>expect </strong>an attack.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.mcafee.com/mcafee-labs/combating-distributed-denial-of-service-attacks-in-brazil-ltam-and-everywhere-else/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>10 Days of Rain in Korea</title>
		<link>http://blogs.mcafee.com/mcafee-labs/10-days-of-rain-in-korea</link>
		<comments>http://blogs.mcafee.com/mcafee-labs/10-days-of-rain-in-korea#comments</comments>
		<pubDate>Tue, 05 Jul 2011 15:57:06 +0000</pubDate>
		<dc:creator>Archive</dc:creator>
				<category><![CDATA[McAfee Labs]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[distributed denial of service]]></category>
		<category><![CDATA[North Korea]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[South Korea]]></category>

		<guid isPermaLink="false">http://blogs.mcafee.com/?p=9854</guid>
		<description><![CDATA[On March 4th of this year, exactly 20 months to the day of a similar incident on US Independence Day in 2009, a botnet based out of South Korea launched Distributed Denial of Service (DDoS) attacks against 40 sites affiliated with South Korean government, military and civilian critical infrastructure as well as U.S. Forces Korea <a href="http://blogs.mcafee.com/mcafee-labs/10-days-of-rain-in-korea">Read more...</a>]]></description>
				<content:encoded><![CDATA[<p>On March 4th of this year, exactly 20 months to the day of a <a href="http://www.foxnews.com/story/0,2933,530560,00.html">similar incident on US Independence Day in 2009</a>, a botnet based out of South Korea <a href="http://www.bbc.co.uk/news/technology-12646052">launched Distributed Denial of Service (DDoS) attacks</a> against 40 sites affiliated with South Korean government, military and civilian critical infrastructure as well as U.S. Forces Korea and the U.S. Air Force Base in Kunsan, South Korea.</p>
<p>Fourteen of the targets were the same as in <a href="http://blogs.csoonline.com/online_attack_hits_us_government_web_sites">the 2009 attacks</a>, but nearly all of the U.S.-based targets such as The White House, State Department, FAA and FTC were removed from the target list. The modus operandi of the attacks was identical and unusually destructive for typical botnet attacks: the botnet, based in South Korea, was dynamically updated via new malware binaries, launched a relentless DDoS for slightly over a week, and then destroyed the machines it was deployed on by overwriting with zeroes and then deleting key data files such as source code, documents and then zeroing-out the Master Boot Record (MBR) to render the computers unbootable.</p>
<p>In March 2011, however, the level of sophistication was dramatically ramped up, especially for something as simple as a DDoS attack. In fact, it was analogous to bringing a Lamborghini to a go-cart race. Multiple encryption algorithms, such as AES, RC4, and RSA were used to obfuscate numerous parts of the code and configuration of the attack components to slow down the analysis. Over 40 globally distributed multi-tier Command &amp; Control servers (USA, Taiwan, Saudi Arabia, Russia and India accounted for over half of all of servers) were used to dynamically update the malware and its configurations in a fashion designed to be highly resilient against takedowns. It was also clear from our analysis of the code that multiple individuals who may not have been in close coordination were responsible for developing its various parts.</p>
<p>So what was the goal of these attacks and why was so much effort employed to do something that’s fairly trivial in this day and age – flood a Web site with purposeless traffic to slow it down or bring completely offline? We believe this incident, which we estimate has a 95% chance of being perpetrated by the same actors as July 4th 2009 attacks, has very clear anti-Korean and anti-U.S. political motivations and potentially is even more insidious. The level of encryption and obfuscation at all layers of the malware and its distribution method, as well as the quick follow-on destruction of data and machines, indicate that one of the key objectives was to impede rapid analysis and remediation by the Korean authorities. This may very well have been a test, an armed cyber reconnaissance operation of sorts, perhaps conducted by the North Korean military as the South Korean National Intelligence Agency has asserted, to test the defenses and more importantly the reaction time of the Korean government and civilian networks to a well-organized and highly obfuscated attack. Knowing that would be invaluable in a possible future armed confrontation on the peninsula, since cyberspace has already become the fifth battlespace dimension, in addition to land, air, sea, and space.</p>
<p>We have published an <a href="https://prod.secureforms.mcafee.com/content/verify?docID=70F85908-BF74-4D45-BA38-835F832447B2&amp;amp;cid=WB247&amp;amp;aName=RC&amp;amp;src=web&amp;amp;aType=white_paper&amp;locale=us">in-depth paper on this incident</a> and McAfee’s analysis of it, detailing information about:</p>
<p>• The target Web sites and methodology of the DDoS attacks<br />
• The different cryptographic algorithms in place and how they have been used to deter analysis<br />
• Interesting mistakes made by the actors involved<br />
• Attribution theory and analysis of intent</p>
<p>As with most initiatives at McAfee, this was a team effort bringing together researchers from McAfee Labs with other departments at McAfee, our partners, and our customers. I would like to give a special thanks to the US-CERT, Department of Defense analysts, and AhnLabs, as well as our own – Dmitri Alperovitch, Brian Contos, Sven Krasser – and countless others for their tireless effort, support, and fighting the good fight every day.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.mcafee.com/mcafee-labs/10-days-of-rain-in-korea/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
