security image

Experts argue over future of DoS

Hackers are likely to drop denial of service attacks as the risks are too great

Written by Phil Muncaster

Widespread denial of service (DoS) attacks could soon be a thing of the past as criminals try to stay undetected and look to find more effective ways of making money, according to managed security specialist Network Box.

Managing director of the firm Simon Heron told IT Week that although attacks may still be launched sporadically out of vindictiveness, they will largely disappear as a means of extorting money from firms, because of the danger of getting caught and the risk of losing control of the bot net.

"This is a risky business because [as a criminal] you're raising your head above the parapet, " he added. "An attack creates an impetus for people to investigate and work out how to find the command and control channel."

Bot nets will instead be used increasingly for other money-making activities such as sending phishing emails, spam and keyloggers to commit identity fraud, Heron argued.

But Andy Kellett of analyst Butler Group said that there are still a lot of money making opportunities for hackers out of DoS attacks, and that the bot nets themselves are now so easy to create that criminals would not be so reluctant to risk losing them.

"There are still times of the year when DoS attacks work well across a number of industries," he added. "It's easy to put together bot nets [which means] they can use them and throw them away, so if they are dying out it's because organisations are finally using the appropriate security solutions to identify them."

Furthermore, DDOS mitigation specialist Prolexic has uncovered new trends in DDOS attacks which show that this form of attack is still a popular way for cyber criminals to make money.

The firm highlighted a new way hackers are using Peer-to-Peer networks in order to control PCs more easily, which involves changing the admin function in the P2P hub server so as to connect all the file sharing PCs to a victim's web server.

"Classically they would put malware on PCs to create a bot net, but this is getting harder to do," explained Prolexic chief technology officer Paul Sop. " So the criminals [found a way] of controlling hundreds of thousands of PCs without talking to them."

Sop added that there is actually very little chance of DOS attackers getting caught today, and that new techniques such as browser-based malware written in JavaScript or Flash and capable of rapid PC infection make the criminal's task much easier.

"This is malware-light but it can still be used to [compromise PCs and] launch full-scale DOS attacks without ever needing to infect the web server," explained Sop. "There's no easy architectural fix for it so we're likely to see it exploited more and more in the future."

Tags:

Further reading

Verizon Business stops DOS attacks

Defense Mitigation Service extended to Europe   More...

Trend appliance sniffs out bot nets

Trend Micro’s new ICSS service could help firms and ISPs spot trojan-infected PCs   More...

VeriSign launches brand and fraud protection services

Secure comms firm announces new ways to protect your reputation and brand   More...

Related articles

Cyber-criminals move with the times

Adware giving way to more serious threats   More...

Skype denies DoS attack on VoIP service

VoIP provider stays tight lipped about cause of outage   More...

Adware tops February malware chart

Kaspersky warns of Virtumonde Trojan downloaders   More...

US surfers 'alarmingly' ignorant over botnet danger

NCSA warns over danger posed by cyber criminals' weapon of choice   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement