Hackers shy away from DDoS attacks

By Tom Espiner, ZDNet UK
Friday, May 04, 2007 07:07 AM

The quantity of distributed denial-of-service attacks launched for the purpose of extortion has fallen, according to security vendor Symantec.

A distributed denial-of-service (DDoS) attack uses a network of compromised computers, known as a 'botnet', to send a large number of packets to a site, causing its server to fall over. Some attackers try to extort money from the site by threatening to launch another attack. However, DDoS attacks are becoming less frequent because of increasing risks to attackers, according to Symantec.

"In the last six months of 2006 we saw a pretty sharp decline in the daily number of denial-of-service attacks. Although there are likely a number of factors at play here, I think there is one primary factor: denial-of-service extortion attacks are no longer profitable," wrote the vendor's security response engineer Yazan Gable in a blog post.

"DDoS is a risky business," Ollie Whitehouse, a Symantec research scientist told ZDNet UK. "DDoS attacks can show how big the attacker's botnet is, and where it's located. There's a risk of the attacker being identified not only by the target and their ISP, but also by their own ISP."

Botnets take time and money to assemble, and increasingly hackers are unwilling to risk DDoS attacks, opting instead for the relatively easy money to be gained from spamming. Revenue gained from phishing and direct sales through spam is increasing, said Symantec. As e-mail spam filter technologies have become more advanced, spammers have turned to easier targets such as blogs. "It's very easy to jump on a blog with an established base and spam that," said Whitehouse.

Detective chief inspector Charlie McMurdie, of the Metropolitan Police Specialist Crime Directorate E-crime Unit, said that DDoS extortion attempts are still being reported to the police but that, without a national unit to collate e-crime information, it was difficult to get an accurate picture of the problem. "We're still having reports made to us, but obviously that's only the tip of the iceberg," McMurdie told ZDNet UK. "We are still receiving reports of attacks, but we've got no national collation of law-enforcement figures as yet."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web