Zombies threaten ISPs
Zombie computers are the single biggest threat to ISPs, according to an annual security survey conducted by Arbor Networks, as compromised PCs are being used to spew out spam, launch distributed denial-of-service (D-DOS) attacks and perpetrate identify theft and phishing schemes.
Industry News
Blogs
Briefing Room
advertisement
About 60% of the ISPs surveyed identified zombies as either their primary or secondary threat, said Mike Hollyman, manager of consulting engineering, for Arbor Networks. Zombies--or “botnet” computers, as they are also known--are PCs linked to the Internet that have been taken over, without their owners’ knowledge, and can be used to send email, store information or run programs. While there is nothing new about botnets, Hollyman said, they are being used more extensively and in different ways.
“They are definitely doing more things – like launching D-DOS attacks, sending spams, serving as open proxies, and being drop sites for storing ID information, and for phishing sites,” he said. By using a widely distributed set of PCs, criminals can use one set of zombies to send out spam with a phishing message and, when an unsuspecting customer provides log-in and identity information, store that on a different zombie computer which can be anywhere in the world, Hollyman said. The traffic flows are more widely distributed and not as easy to detect.
“That makes it harder for law enforcement to track down,” he said. “The way they are created these days, it is easy to select individual hosts they want to use in nefarious ways. They may pick a botnet for a phishing attack that is in a site where there is no legal enforcement or the resources are limited.”
According to survey respondents, networks of zombies have become smaller and more adaptive, with “more firepower and more effective attack vectors,” Arbor reports, as well as better organized command and control servers that use peer-to-peer communications.
D-DOS attacks are the most common use of botnets and can take down Web sites and e-commerce operations, Hollyman said. Survey respondents say these attacks are getting more professional and therefore more disruptive.
“The largest attack has gone up to 24 Gb/s, which is 2.5 times the average link speeds,” he said. “One of those attacks could cause severe collateral damage, and we have seen that in last 12 months. As service providers start to monitor deeper into their networks, they are seeing these attacks might be impacting their infrastructure.”
That means an attack against a specific customer site – and most attacks are that specific – has collateral impact on other customers served by the same network aggregation device.
Service providers are acquiring in-house expertise to address security issues as concerns have grown, Hollyman said, but they could use more help from law enforcement.
“They are proving they have the in-house skills, and they are no longer just packet pushers, they are in the position to gather information from security that will lead to global changes to attack vectors,” he said. “What they need now is better law enforcement options. Today, the response is fragmented. Many attacks involve multiple providers and multiple law enforcement entities and that can be difficult to manage.”
Want to use this article? Click here for options!
© 2012 Penton Media Inc.
advertisement
Learning Library
Webcasts
Using Real-Time Offers, Alerts and Interactions To Improve the Mobile Broadband Experience
In this Webinar you will learn how to create a real-time relationship with your customers, how to proactively improve the customer experience, and how to successfully target and cross-sell services to boost incremental revenue.
- Megabytes to Megabucks, Bandwidth to Business Models: How 4G Is Changing Everything
- How to Unplug Your Redundant Telco Apps To Save Money and Improve Efficiency
- When IaaS Isn't Enough: Service Provider Business Models to Drive Growth and Build Margin
- How to Transform Your Aging Telco Voice Network to Drive New Profits and Revenue
- Creative Licensing Approaches for Telcos & Their Network Equipment Vendors
- Smart Home Opportunity: Balancing Customer Data & Privacy
White Papers
The Role of Diameter in All-IP, Service-Oriented Networks
This paper discusses the rise of Diameter and benefits of Diameter Protocol.
- Conducting The Orchestration – Order Management at the Speed of Business
- Toward a Converged Network Edge
- Beyond Spam – Email Security in the Age of Blended Threats
- 6 Important Steps to Evaluating a Web Filtering Solution
- The Expertise to Protect You from Botnet and DDoS Attacks
- Seeing is Believing – Bridging the Order Visibility Gap
Featured Content
A time and money saving approach to fiber deployment
Service providers are under tremendous pressure to turn up new services faster then before and, at the same time,
to do it at less expense - and intra-office fiber is one of the biggest challenges in terms of both cost and service
turn-up.
of interest
The Latest
News
From the Blog
Briefingroom
Join the Discussion
Resources
Get more out of Connected Planet by visiting our related resources below:
Connected Planet highlights the next generation of service providers, as well as how their customers use services in new ways.
Subscribe Now







