Criminal economy is evolving around denial of service activity, says Arbor Networks
October 11, 2005
Cyber fraud, distributed denial of service attacks (DDoS) and other intrusions continue to pose a significant and growing challenge for service providers.
Arbor Networks released its first worldwide Internet Service Provider (ISP) security report today.
The report - which surveyed tier 1 ISPs, large content and hosting providers, tier 2 network operators and large broadband and dial-up network operators around the world -found that DDoS attacks are still the most crippling threat facing ISPs.
The network security experts responding to the survey said the motivations for the daily DDoS attacks were cyber terrorism/warfare; corporate espionage; extortion; disputes between adolescents on gaming sites and cyber protests.
In addition to identifying DDoS attacks as the primary threat facing the service provider community today, the survey also revealed:
-- While only 29% of the respondents offer security and DDoS-related SLAs to their enterprise customers, the survey concluded that the increasing number and size of the attacks will lead to more DDoS prevention services in the future;
-- The majority of service providers responding to the survey said that compromised hosts -- commonly referred to as zombies or bots -- are everywhere. All respondents reported attacks involving thousands of compromised hosts, and that zombie networks, or botnets, are employed in well over half of all DDoS events;
-- Service providers that deployed botnet measurement and detection tools placed the largest botnet army observed in a single attack at approximately 20,000 infected hosts and up to one Gigabit;
-- Almost 30% of the service providers noted that the primary threat from worms is not their payloads, but the network congestion and subsequent denial of service they cause.
"This survey quantifies what industry insiders have known for quite some time," said Yankee Group Analyst Chris Liebert. "Denial of service and fast propagating worms are real problems for worldwide ISPs, and they continue to struggle with these attacks that are made against their customers. While these attacks often do not harm the ISP's network, they easily take down service to their customers. ISPs need to do everything possible to protect their clients from denial of service attacks and other Internet threats."
As security threats become more sophisticated and destructive, Arbor hopes that the findings within this report will assist ISPs as they make decisions on how to protect their mission-critical infrastructure.
"We conducted this report to uncover service providers' greatest security worries and to illuminate some of these security challenges that take place behind the scenes," said Danny McPherson, director of business research at Arbor Networks. "The report clearly indicates that an entire criminal economy is evolving around denial of service activity -- driving some service providers to offer new network-based security services to combat these attacks."