2018年夏季互联网现状-安全_Web_攻击(英文版)-3mb
报告摘要
SOTI SUMMER 2018: State of the Internet / Security Summary
Core Content
The SOTI SUMMER 2018: State of the Internet / Security: Web Attack report highlights the evolving landscape of web-based attacks, particularly DDoS (Distributed Denial of Service) and credential abuse, across various industries. It outlines the trends, new attack vectors, and law enforcement responses to these threats.
Main Points and Key Information
DDoS Attack Trends
- Overall Increase: DDoS attacks increased by 16% in Summer 2018 compared to Summer 2017.
- Infrastructure Layer Attacks: These increased by 16%, with a new memcached reflection vector emerging as a significant threat.
- Reflection-Based Attacks: Increased by 4%, but not as dramatically as other types.
- Application Layer Attacks: Rose by 38%, indicating a shift in attack strategies.
Key Observations
- Memcached Attack: The largest DDoS attack recorded by Akamai reached 1.35 Tbps, breaking the 1 Tbps threshold.
- Mitigated Attacks: Akamai mitigated 7,822 DDoS attacks during the summer.
- New Attack Vectors:
- Multi-vector reflection attacks using obscure protocols like IPMI and IKE.
- Mirai attacks continued, with new variants being observed.
- Law Enforcement Action:
- Operation Power Off was a joint effort by the Dutch National High Tech Crime Unit and the UK National Crime Agency.
- The DDoS-for-hire platform Webstresser.org was taken down, and its administrators arrested.
What You Need to Know
- The Web Attack report will now be published twice a year.
- DDoS attacks are not just about volume; they are becoming more sophisticated.
- Credential abuse is a major concern, especially in the hotel and travel industries.
- Russia and China are significant sources of credential abuse attacks against these industries.
- Akamai has observed a pattern where a small number of networks are responsible for a large proportion of attacks.
Emerging Threats
- Memcached DDoS:
- A new vector that allowed for amplification at a much higher rate than previous reflection attacks.
- The attack peaked at 1.35 Tbps, which is nearly the capacity of some undersea cables.
- The attack was coordinated via YouTube tutorials, involving 12-year-old developers and peer-to-peer coordination.
- The attack included SYN Floods (over 170 Gbps and 65 Mpps) and POST Floods.
- Collateral Damage:
- Flooding an entire /24 subnet can impact secondary servers within the same network.
- Defenders should prioritize identifying and mitigating core assets and consider packet captures for forensic analysis.
- Adaptive Attackers:
- Attackers adjust their tactics based on mitigation efforts.
- PSH/ACK traffic was used to supplement DNS attacks, making them more difficult to defend against.
Abusing Hospitality
- Bot Traffic:
- Akamai recorded 112 billion bot requests and 3.9 billion malicious login attempts across hotel, travel, and related industries.
- Hotel and resort sites experienced the most credential abuse connections, surpassing airlines and cruise lines.
- Bot Categories:
- Impersonators of known browsers: 40% of traffic.
- Other Bots: 20% of bot traffic, often used to evade detection.
- Search Engine Bots: Significant presence, but can cause server overload if not managed.
- Geographic Origins:
- Russia, China, and Indonesia are the primary sources of credential abuse.
- United States is both the largest source and destination of such attacks.
- Attackers may not be located in the same region as the compromised systems, which can be used as proxies.
Operation Power Off
- Target: The DDoS-for-hire platform Webstresser.org.
- Impact:
- Served over 136,000 users and launched 4-6 million attacks.
- Took down a platform responsible for attacks on Dutch financial organizations.
- Arrests: Admins were based in UK, Croatia, Canada, and Serbia and were arrested in a coordinated law enforcement effort.
- Infrastructure Seizure:
- Seized in Netherlands, Italy, Spain, Croatia, UK, Australia, Canada, and Hong Kong.
- Monetization:
- Users could pay as little as $25 to launch attacks.
- Accepted PayPal and Bitcoin for payments.
Looking Forward
- The report format is evolving to be shorter and more focused, with biannual releases.
- Technology such as IoT and AI is being exploited by attackers, highlighting the need for proactive security strategies.
- Collaboration between manufacturers, technologists, and security professionals is essential for staying ahead of emerging threats.
- Security must be embedded in every aspect of business, not just a reactive measure.
- Continuous monitoring and forensic analysis are critical for identifying and responding to attacks effectively.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载