Advertisement
Promo

Online business Toolkit

Study: Hackers take a trip through Asia

Published: 19 Mar 2002 11:14 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Servers based in South Korea and China are the most commonly used in attacks on the Internet, following servers housed in the United States, according to a study released Monday by an infrastructure consulting firm.

Using its more than 50 sensors around the Internet to study more than 12 million probes and attacks, New York-based Predictive Systems found that 49 percent of all attacks took advantage of servers in the United States, 17 percent used South Korean servers, and about 15 percent used servers based in China.

While the results don't suggest which nations have the most hackers, they do indicate that unsecured infrastructure is often co-opted by attackers in other countries and poses a significant risk to others connected to the Internet, said Richard Smith, a senior information security analyst with Predictive.

"Countries that are not technologically advanced or very high up on the security evolution chain had a higher probability" of seeing their servers used in attacks, Smith said, adding that "those with more users also gravitated to the top."

The United States has the largest Internet infrastructure and most online users, so it's no surprise that it takes the top slot, Smith said. The fact that servers in South Korea and China are used in so many attacks should be a wake-up call for the countries, he said.

"South Korea has a large broadband population, so they are especially at risk," Smith said, adding that between always-on broadband connections and poor user education, the country is a perfect launching point for attacks.

Despite post-September 11 doomsday prophesies regarding attacks over the Internet by religious factions in the Middle East, servers in Middle Eastern countries didn't account for a significant number of attacks.

"The main thing is that they don't have the infrastructure yet," Smith said. "Broadband and dial-up services are very expensive, and in many places, they don't really have a telecommunications infrastructure yet, not to say a data infrastructure."

Predictive focused on more than 12 million "events" that the company's 54 sensors, which monitor the firm's clients, detected in the last quarter of 2001. Each event could be a simple scan of a service -- such as email, file sharing or a Web site -- offered by a server, a probe for a specific vulnerability, or a real attack.

By correlating the Internet address of the source of the event with addresses owned by Internet service providers in each country, Predictive could determine the last server from which an attack came.

However, the country from which the hacker is truly attacking remains a mystery, Smith said.

"There is no way of really knowing the original source without getting access to the logs to see if the attacks originate there or they use the (country) as a jumping point," Smith said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
59 out of 118 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:













Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters