ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Networks hit by co-ordinated attack

Will Knight ZDNet.co.uk

Published: 08 Dec 1999 13:28 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Further evidence of a new type denial of service (DoS) attacks with unparalleled potential for causing havoc has been uncovered by Internet Security Systems (ISS).

The attack involves co-ordinating a simultaneous DoS strike from an unusually large number of compromised and remotely controlled machines. ISS has issued an alert warning that a number of high capacity networks have already been subjected to this radical new type of onslaught.

This new approach to attacking a network was uncovered at the National Information Systems Security Conference in the US. Now, however, there is more evidence of how significant the approach is becoming.

The ISS alert describes the attack in uncompromising terms, calling it "more powerful than any previous DoS attack observed on the Internet," and adding that "ISS considers this attack as a high risk since it can potentially impact a wide number of organisations. It has proven to be successful and is difficult to defend against."

According to ISS, two exploit applications are being used particularly to formulate this sort of attack: trin00 and Tribe Flood Network (TFN).

John Hayday, director of knowledge services at ISS's X-Force research labs outlines the significance of this emerging trend in computer attack saying: "These tools are designed to take attacks a stage further. They allow someone to stand back from the machined. It is automating the process that much more."

Hayday also says that there are two ways of countering this particular style of assault. First of all it is possible to have a piece of software that will analyse traffic and recognise that you are being targeted in a co-ordinated DoS attack. Secondly, you run something on your host that will make sure you don't have broadcast agents on it. ISS is currently working on such counter-measures and estimates that an update to its Internet Scanner application will enable it to scan for such behaviour as well as TFN and trin00 will be available from 30 December.

One professional security consultant, Ian Johnston-Bryden of Oceanus security says that although this isn't a ground-breaking discovery, it does illustrate an important direction because it makes it far more difficult trace an attack efficiently. "It's certainly quite easy to put this sort of thing together," he says. "But it is very difficult to be completely sure that it is actually a denial of service attack. I'm fairly sure it's going to be used much more for political attacks on Web sites. In HM government this is something that they are becoming increasingly concerned about."

Take me to the Hackers news special

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
81 out of 121 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

UNIX/NETWORK SYSTEMS ADMINISTRATOR

This is a great role for someone who wants to be involved during a critical stage in the development of what is becoming an iconic luxury e-tailing ...

Urgent requirement! - ASP.Net Developer (C# or VB.Net) - Milton Keynes

We have immedate one-stage interviews available. This is an immediate requirement with one-stage interviews available. An ASP.NET (C# or VB.Net) SQL, ...

Web Developer, Solihull, 30-35k

If this sounds like the sort of role that you are seeking then apply now with your up to date CV. A highly successful international marketing and ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains