Advertisement
Promo

Security threats Toolkit

Hackers shy away from DDoS attacks

Tom Espiner ZDNet.co.uk

Published: 03 May 2007 12:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The quantity of distributed denial-of-service attacks launched for the purpose of extortion has fallen, according to security vendor Symantec.

A distributed denial-of-service (DDoS) attack uses a network of compromised computers, known as a botnet, to send a large number of packets to a site, causing its server to fall over. Some attackers try to extort money from the site by threatening to launch another attack. However, DDoS attacks are becoming less frequent because of increasing risks to attackers, according to Symantec.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

"In the last six months of 2006 we saw a pretty sharp decline in the daily number of denial-of-service attacks. Although there are likely a number of factors at play here, I think there is one primary factor: denial-of-service extortion attacks are no longer profitable," wrote the vendor's security response engineer Yazan Gable in a blog post.

"DDoS is a risky business," Ollie Whitehouse, a Symantec research scientist told ZDNet UK. "DDoS attacks can show how big the attacker's botnet is, and where it's located. There's a risk of the attacker being identified not only by the target and their ISP, but also by their own ISP."

Botnets take time and money to assemble, and increasingly hackers are unwilling to risk DDoS attacks, opting instead for the relatively easy money to be gained from spamming. Revenue gained from phishing and direct sales through spam is increasing, said Symantec. As email spam filter technologies have become more advanced, spammers have turned to easier targets such as blogs. "It's very easy to jump on a blog with an established base and spam that," said Whitehouse.

Detective chief inspector Charlie McMurdie, of the Metropolitan Police Specialist Crime Directorate E-crime Unit, said that DDoS extortion attempts are still being reported to the police but that, without a national unit to collate e-crime information, it was difficult to get an accurate picture of the problem. "We're still having reports made to us, but obviously that's only the tip of the iceberg," McMurdie told ZDNet UK. "We are still receiving reports of attacks, but we've got no national collation of law-enforcement figures as yet."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
14 out of 21 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters