Advertisement
Promo

Online business Toolkit

Study: Hackers take a trip through Asia

Published: 19 Mar 2002 11:14 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Servers based in South Korea and China are the most commonly used in attacks on the Internet, following servers housed in the United States, according to a study released Monday by an infrastructure consulting firm.

Using its more than 50 sensors around the Internet to study more than 12 million probes and attacks, New York-based Predictive Systems found that 49 percent of all attacks took advantage of servers in the United States, 17 percent used South Korean servers, and about 15 percent used servers based in China.

While the results don't suggest which nations have the most hackers, they do indicate that unsecured infrastructure is often co-opted by attackers in other countries and poses a significant risk to others connected to the Internet, said Richard Smith, a senior information security analyst with Predictive.

"Countries that are not technologically advanced or very high up on the security evolution chain had a higher probability" of seeing their servers used in attacks, Smith said, adding that "those with more users also gravitated to the top."

The United States has the largest Internet infrastructure and most online users, so it's no surprise that it takes the top slot, Smith said. The fact that servers in South Korea and China are used in so many attacks should be a wake-up call for the countries, he said.

"South Korea has a large broadband population, so they are especially at risk," Smith said, adding that between always-on broadband connections and poor user education, the country is a perfect launching point for attacks.

Despite post-September 11 doomsday prophesies regarding attacks over the Internet by religious factions in the Middle East, servers in Middle Eastern countries didn't account for a significant number of attacks.

"The main thing is that they don't have the infrastructure yet," Smith said. "Broadband and dial-up services are very expensive, and in many places, they don't really have a telecommunications infrastructure yet, not to say a data infrastructure."

Predictive focused on more than 12 million "events" that the company's 54 sensors, which monitor the firm's clients, detected in the last quarter of 2001. Each event could be a simple scan of a service -- such as email, file sharing or a Web site -- offered by a server, a probe for a specific vulnerability, or a real attack.

By correlating the Internet address of the source of the event with addresses owned by Internet service providers in each country, Predictive could determine the last server from which an attack came.

However, the country from which the hacker is truly attacking remains a mystery, Smith said.

"There is no way of really knowing the original source without getting access to the logs to see if the attacks originate there or they use the (country) as a jumping point," Smith said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
59 out of 118 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:













Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters