Showing posts with label botnet detection. Show all posts
Showing posts with label botnet detection. Show all posts

Friday, March 23, 2012

US ISPs Agreed to Combat Major Cyber Security Threats


While US ISPs get ready to fight piracy by watching for illegal content downloads (here) they have also agreed to ".. better secure their communications networks and protect consumers and business".
  
An FCC press release announced that ".. an industry advisory group for the Federal Communications Commission (FCC), the Communications, Security, Reliability, and Interoperability Council (CSRIC), unanimously adopted recommendations for voluntary action by Internet service providers (ISPs) to combat three major cyber security threats, including botnets, attacks on the Domain Name System (DNS), and Internet route hijacking .. Chairman Genachowski applauds voluntary commitments by nation’s largest Internet Service Providers, including AT&T, CenturyLink, Comcast, Cox, Sprint, Time Warner Cable, T-Mobile and Verizon".
  • Under the Anti-Bot Code, ISPs agree to educate consumers about the botnet threat, take steps to detect botnet activity on their networks, make consumers aware of botnet infections on their computers, offer assistance to consumers whose computers are infected and collaborate with other service providers that have also adopted the Anti-Bot Code
      
  • DNSSEC is a set of secure protocol extensions that prevent such fraudulent activity
      
  • CSRIC recommended an industry framework to prevent Internet route hijacking, which is the erroneous routing of Internet traffic through potentially untrustworthy networks 
Some examples from other countries: Sri-Lanka, Nigeria, Egypt, India, Korea, Argentina. AT&T also announced several security initiatives (here here and here).    

See "FCC advisory committee adopts recommendations to minimize three major cyber threats, including an anti-bot code of conduct, ip route hijacking industry framework and secure DNS best practices" - here and more details (here).

Friday, July 15, 2011

Gartner: "it is time to have DDoS protection considered "

   
John Pescatore (pictured), VP Distinguished Analyst at Gartner, explains that "There have definitely been environmentally caused Internet outages, but in this case denial of service attacks are the leading cause. There are low scale attacks that anyone who can spell LOIC can launch and then there are large scale distributed attacks that take a bit more knowledge of botnets and the like, but DoS attacks are basically like thunderstorms on the Internet: hard to predict when they will hit, but they will and you can build a thunderstorm-proof Internet connection – just the way you can have thunderstorm proof power to your datacenter".

See "Still in Denial About Denial of Service?" - here.

See also - "Yankee Group Prediction: A Denial-of-Service Attack Will Take a 4G Network Down" - here, and "DPI: NSA Scans AT&T, Verizon and CenturyLink Traffic Going to Defense Firms" - here, with a short review of solutions from the DPI players.

Sunday, July 3, 2011

Arbor Mitigates DDoS Attacks in IPv6

  
Arbor Networks announced recently the "availability of version 5.6 of Arbor Peakflow SP .. platform to proactively fend off malicious threats such as botnets and volumetric and application-layer distributed denial of service (DDoS) attacks"

Among other new features, and following the recent interest in IPv6 (see stories about "World IPv6 Day" - here, here), the new version "adds the capability to mitigate attacks over IPv6. First, the highly effective Peakflow SP TMS mitigation architecture available for IPv4 networks is now available for IPv6. Operators can use techniques such as Remote Triggered Blackhole Routing (RTHB) and TMS diversion/reinjection to quickly and effectively deal with attacks over IPv6. Second, the release provides a comprehensive suite of IPv6 threat countermeasures, enabling the TMS system to screen out IPv6 attack traffic, while allowing legitimate traffic to reach the intended destination".

The release does not mention if the support for IPv6 has performance effects, as may happen in such cases.

See "Arbor Networks Introduces Peakflow SP 5.6" - here.


Friday, July 1, 2011

How to Build DPI Products? (Part X - Botnet Detection)

 
This time - a presentation made during ASIACCS 2011 earlier this year titled "Boosting the scalability of Botnet Detection Using Adaptive Traffic Sampling" - by Junjie Zhang, Xiapu Luo, Roberto Perdisci, Guofei Gu (picture), Wenke Lee and Nick Feamster.

See slides here.

Related post - "ALU Bell Labs: Network Behavior Analysis Helps to Detect Malware Infection" - here.


Friday, January 21, 2011

ALU Bell Labs: Network Behavior Analysis Helps to Detect Malware Infection

 
A recent article by Jin Cao (picture), Laurent ClevyLawrence Menten all from Bell Labs, Alcatel-Lucent discusses "Network detection techniques offer an alternative to existing tools such as antivirus software and personal firewalls. This article will review these challenges and the unique approaches by Alcatel-Lucent Bell Labs researchers for using network behavior analysis to detect malware infection".

See "Security: On the Trail of the Elusive Botnet" - here.

"Current detection methods focus on malware detection software that scans individual computers. However, antivirus software and personal firewalls have proven inadequate. Botnet authors thoroughly test their creations to evade detection, but some malware simply disables these protection mechanisms ... Alcatel-Lucent Bell Labs researchers are working closely with security and product development teams to develop a broad set of network-based botnet detection techniques that can be incorporated into products. Three of the techniques are:
  • Offline data mining and statistical analysis
  • Behavioral analysis of network traffic at the endpoint
  • Analysis of DNS packets at the network perimeter"
See a related post on implementation of DDoS, Botnets and infected subscribers detection - here (such as the chart below, from Allot Communications, demonstrates).