ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Symbiot launches DDoS counter-strike tool

Munir Kotadia ZDNet.co.uk

Published: 10 Mar 2004 15:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Symbiot, a Texas-based security firm, is preparing to launch a corporate defence system at the end of March that can fight back against distributed denial-of-service (DDoS) and hacker attacks by launching a counter-strike.

In advance of the product launch, Symbiot's president, Mike Erwin, and its chief scientist, Paco Nathan, have outlined a set of "rules of engagement for information warfare", which they say should be part of corporate security policy to help companies determine their exact response to an incoming attack.

"Until today, security solutions have been totally passive in nature. Merely erecting defensive walls around the perimeter of an enterprise network is not an adequate deterrent," said Erwin, who argues that to have a complete defence in place, offensive tactics must be employed. The company said it bases its theory on the military doctrine of "necessity and proportionality", which means the response to an attack is proportionate to the attack's ferocity. According to the company, a response could range from "profiling and blacklisting upstream providers" or it could be escalated to launch a "distributed denial of service counter-strike".

Security experts expressed alarm at the company's plans.

Graham Titterington, principal analyst at Ovum, said "such a counterattack would not be regarded as self-defence and would therefore be an attack. It would be illegal in those jurisdictions where an anti-hacking law is in place." He added that because many hacking and DDoS attacks are launched from hijacked computers, the system would be unlikely to find its real target: "Attacks are often launched from a site that has been hijacked, making it an unwitting and innocent -- although possibly slightly negligent -- party."

Richard Starnes, director of incident response at Cable and Wireless Managed Security Services, said he would not employ an "active defence technique" because there are legal and ethical issues involved. Also, he would not be happy about any product "specifically designed to launch attacks" being put into commercial production. Starnes said it would be easy to hit the wrong target and even if it was the right target, there could be collateral damage: "You may be taking out grandma's computer in Birmingham that has got a 100-year-old cookie recipe that has not been backed up. The attack could also knock over a Point of Presence (PoP), so you are not only attacking the target, but also the feeds before them -- this means taking out ISPs, businesses and home users."

Jay Heiser, chief analyst at IT risk management company TruSecure, said that he expects the product to have "emotional appeal" to companies that have been targets, but "that is a very bad criterion for choosing risk-reduction measures."

"There is no evidence that this is the most effective way to deal with the problems and there is quite a bit of historical precedence that indicates it is totally counterproductive," added Heiser.

Governments could soon be using hacker tools for law enforcement and the pursuit of justice, according to an expert on IT and Internet law. Joel Reidenberg, professor of law at New York-based Fordham University, believes it likely that denial of service attacks (DoS) and packet-blocking technology will be employed by nation states to enforce their laws. This could even include attacks on companies based in other countries, he says.

ZDNet UK's Graeme Wearden contributed to this story.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
94 out of 173 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Counter Analyst Programmer

Counter Analyst Programmer Knutsford, Cheshire competitive depending on experience (+exceptional benefits) Purpose of Role The role is on an ...

Excellent IT Engineer at Exclusive HedgeFund - London and New York!

Boutique Capital Management co, based in Mayfair has a rare PERM position for Infrastructure Support Analyst. This IT Engineer will firstly be based ...

Project Manager - APPLY NOW (Aerospace & Defence)!

A leading Aerospace and Defence organisation is currently seeking a Project Manager to join their team. As the Project / Program Manager you will ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation