Just in:
Telecom Giant Du Eyes Crypto Integration for FinTech Platform // UAE President, Spanish Prime Minister Hold Phone Talks // Etihad Airways Announces Paris Service with A380 // Cobb’s Game-Changer: Introducing One-Stop Event Transport Management Solution // Why Lok Sabha Election For 20 Seats In Kerala Is Crucial For Future Of Left In Indian Politics? // Abu Dhabi Secures US$5 Billion in Fresh Funding // World Intellectual Property Day: OPPO Maintains Top 10 Global IP Ranking for Fifth Consecutive Year // Lai & Turner Law Firm PLLC Welcomes Eric Strocen as Director of Family Law Division // ZUHYX Exchange: Embracing Social Responsibility for a Sustainable Future // New Dynamics in Cryptocurrency Security: ZUHYX Builds the Strongest Fund Protection System // Dubai Gears Up for Second FinTech Summit as Funding Surges // Downpours in Oman and UAE Likely Amplified by Warming Planet // Booming Region Fuels Innovation Surge // Ministry of Agriculture Supports Taiwanese Tea’s Entry into Singapore Market to Boost Global Presence // Prince Holding Group’s Chen Zhi Scholarship Clinches Silver Stevie for CSR Excellence at Asia-Pacific Stevie Awards // Leading with Compliance, ZUHYX Earns the Canadian MSB License // Cairo Recognizes Arab World’s Creative Luminaries at Award Ceremony // TPBank and Backbase Clinch ‘Best Omni-Channel Digital CX Solution’ at the Digital CX Awards 2024 // DIFC Courts Cement Role as Top English Dispute Resolution Choice // Sharjah Census Gears Up for Final Enumeration Phase //

Mirai DNS Water Torture finance sector attack dominated Q1: Akamai

1495068814 mirai dns water torture attack akamai

mirai-dns-water-torture-attack-akamai.png

Mirai DNS Water Torture attack payload, with target domain names redacted

Mirai DNS Water Torture distributed denial of service (DDoS) attacks dominated the first quarter of 2017, a report from Akamai has found.

According to Akamai’s State of the Internet/security Q1 2017 report, Water Torture attacks using this DNS query vector were first observed on January 11, 2017, targeting several of the company’s customers in the financial services industry.

ADVERTISEMENT

The attack activity began with five consecutive days of attacks — when one of three DNS servers received 14 Mbps of attack traffic — followed by a four-day reprieve before concluding with a final attack on January 20, 2017.

Water Torture follows normal DNS recursion paths, Akamai explained, and as a result, the attacker cannot select a specific IP address at the target site.

“Although DNS query attacks are not as common as DNS reflection attacks, this DNS query flood can potentially cause more damage than current DNS reflection attacks,” Akamai wrote. “If a targeted DNS server is unprepared for a sustained flood of queries with high packet rates.”

The Mirai DNS query flood does not use reflection or spoofing techniques, nor does it allow attackers to specify a target IP, rather it accepts a domain name as the target for a DNS cache-busting flood.

A randomised 12-character alphanumeric subdomain is prepended to the target domain and the attacking bots send their queries to their locally-configured DNS servers, which are typically DNS servers at local ISPs.

According to Akamai, the randomised subdomain is present to ensure that no intermediate recursive DNS server would have the response for that name cached locally, but, since the response cannot be cached, every query follows the usual path until it reaches an authoritative DNS server, which is the real target of the attack.

As a result, Water Torture can lead to a denial of service for legitimate users as each query ties up memory and processor cycles, preventing the target from processing legitimate traffic.

“If our analysis of Q1 tells us anything, it’s that risks to the internet and to targeted industry sectors remain and continue to evolve,” said Martin McKeay, senior security advocate at Akamai.

“Use cases for botnets like Mirai have continued to advance and change, with attackers increasingly integrating Internet of Things vulnerabilities into the fabric of DDoS botnets and malware.”

According to McKeay, it is a short-sighted approach to think of Mirai as the only threat, as with the release of the source code, any aspect of Mirai could be incorporated into other botnets.

“Even without adding Mirai’s capabilities, there is evidence that botnet families like BillGates, elknot, and XOR have been mutating to take advantage of the changing landscape,” he added.

The report also found there was a 35 percent year-over-year increase in total web application attacks from Q1 2016, as well as a 57 percent increase in attacks originating from the United States — which is the top attack source country.

There was a 30 percent decrease in total DDoS attacks; a 28 percent decrease in infrastructure layer three and four attacks; a 19 percent decrease in reflection-based attacks; and an 89 percent decrease in attacks greater than 100 Gbps over quarter one last year.

Akamai compiled its latest report [PDF] from analysis and research based on data from its global infrastructure and routed DDoS solution.

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
Telecom Giant Du Eyes Crypto Integration for FinTech Platform // Oman Seeks Growth Through Strategic Economic Alliances // Cobb’s Game-Changer: Introducing One-Stop Event Transport Management Solution // Ministry of Agriculture Supports Taiwanese Tea’s Entry into Singapore Market to Boost Global Presence // Emirates to Embrace Electric Seaglider Travel // Lai & Turner Law Firm PLLC Welcomes Eric Strocen as Director of Family Law Division // New Dynamics in Cryptocurrency Security: ZUHYX Builds the Strongest Fund Protection System // Sharjah Census Gears Up for Final Enumeration Phase // Booming Region Fuels Innovation Surge // Downpours in Oman and UAE Likely Amplified by Warming Planet // GE Jun, Chairman and CEO of TOJOY, Delivers an Inspiring Speech: “Leaping Ahead Again” // DIFC Courts Cement Role as Top English Dispute Resolution Choice // World Intellectual Property Day: OPPO Maintains Top 10 Global IP Ranking for Fifth Consecutive Year // UAE Scrutinizes Report on Racial Discrimination Treaty // ZUHYX Exchange: Embracing Social Responsibility for a Sustainable Future // Lee Chong Wei Shows Up On Chinese Hot cultural Talk Show “SHEDE Wisdom Talents”, Talking About “Crossing The Hill” // Galaxy Macau’s Sakura Cultural Festival Kicked off in Splendor // AVPN Charts Path Forward at 2024 Global Conference // UAE President, Spanish Prime Minister Hold Phone Talks // Prince Holding Group’s Chen Zhi Scholarship Clinches Silver Stevie for CSR Excellence at Asia-Pacific Stevie Awards //