Sunday, 30 May 2010
Need a botnet, only $9.00 the hour
Posted by
Arturo Servin
at
05:09
0
comments
Labels: botnets. ddos, Denial of Service, IT security
Saturday, 8 August 2009
DoS/DDoS news resources
Considering the hype about DoS and DDoS in the last days as consequence of attacks to Twitter, Facebook and LiveJournal I decided to include some of my information sources in this blog. I did some redesign of the right bar. I included some DoS and DDoS news, they are a set of news manually selected by me. I take the news from different sources and I apply some basic filtering and data-mining I come with them. They can be also accessed here if you want to include them in your RSS reader.
"Security news from Twitter" are posts about DoS/DDoS attacks collected from twitter. This is a little bit noisy with around 30-50 posts per day. Some of the posts are repeated or uninterested (from my perspective) but it works as a source for my tools that extract some information for them. The raw feeds are here and here.
Finally I included some general IT security news from twittsecurity. Twittsecurity is a bot that shares security news in Twitter. It searches and selects IT security news using a hybrid method (automatic and human assisted). Feel free to follow it.
Posted by
Arturo Servin
at
06:56
1 comments
Labels: DDoS, Denial of Service, Distributed Denial of Service, dos, IT security, twitter
Tuesday, 28 April 2009
SPAM and the commerce of fear
A few days ago I commented that the spammers would soon begin sending mails about medication against the swine flu and replacing the old viagra SPAM. Shortly after, the US-CERT warned of phishing attacks using this new vector for social engineering and the SANS published a list of sites that could generate malware/phishing /scams (according to the particular domain names selected).
Well today I received my first flu-related SPAM. Also, visiting a news site I found this ad from Google Ads. The ads are not malware sites (at least these three do not appear to be, but try them at your own risk), but certainly they plan to profit from the people's fear.
Well, I think that we humans are quite predictable.
Posted by
Arturo Servin
at
04:07
0
comments
Labels: flu, IT security, phishing, SANS, scam, spam, swineflu
Wednesday, 1 April 2009
The big news today about Conficker ... is that there is no news
For the moment everything looks calm. Although it is almost April 1 throughout the whole world there is not yet any news about of the end of the world. Today, the media expected big problems as result from the spreading of the worm conficker and the new "payload" that would be activated.
More than a result of a large patch campaign, I think that the famous worm exploited a large media campaign that exaggerated and overestimated its effects. I expect this to be just another day in the life of a security research. Anyway, if something happens, I will be updating my twitter and my tumbr (this is Spanish only). In case of infection or pro-action against the worm, here are some resources.
Posted by
Arturo Servin
at
02:42
0
comments
Labels: Denial of Service, Distributed Denial of Service, IT security, worm
Monday, 16 March 2009
The BBC, the botnet and other DDoS attacks
In other news, Jose Nazario of Arbor Networks in hiss presentation at SOURCE Boston commented about the new "trends" in cyber crime. Nazario said that cyber criminals are not just selling kits for running malicious software on unprotected computers. Now they sell services for script-kiddies and criminals who are just not good enough to use the malware by themselves. The audio of the presentation here.
The DDoS attack to the torrent site Mininova continued during this week. Here you can see some trends in traffic that the attacks have generated.
Posted by
Arturo Servin
at
09:51
0
comments
Labels: DDoS, Distributed Denial of Service, dos, IT security
Sunday, 8 March 2009
DDoS in March
To the surprise of some, the Pirate Bay website was under a DDoS attack earlier this week. Still no news about the intellectual authors. The site is stable for now.
According to an analysis of the anti-virus firm Sophos, the worm Confiker could start a DDoS attack to some sites, including Soutwest Airlines. The collateral damage would be a DoS due to the spread of the worm. The note on TechRepublic.
And the torrent's site Minova has been attacked by a DDoS. According to TorrentFreak the attack has reached the 2 Gbps peak. It seems to come from bot networks that appear to be in Germany and Argentina.
Posted by
Arturo Servin
at
05:23
0
comments
Labels: DDoS, Denial of Service, dos, IT security, worm
Wednesday, 10 December 2008
Le Monde (the translated version here) reports that the web site of the French Embassy in China has been inaccessible for a few days. The cause is an apparently DDoS. The attack seems to be a consequence of the political tensions between China and France as result of the meeting of the french president Sarkozy with the Dalai Lama in Poland.
Posted by
Arturo Servin
at
01:36
0
comments
Labels: DDoS, dos, IT security
Wednesday, 4 June 2008
DoS video with captions
Well, I started to play with the new YouTube feature to add captions to your video. I think that my video of the DoS attack simulation is better explained with captions. This is the same video that I have used in some of my research work and paper presentations.
I do not why but the embedded video did not show the captions, so the link is here.
Posted by
Arturo Servin
at
06:39
0
comments
Labels: Denial of Service, dos, google, IT security, simulation, youtube
Friday, 22 February 2008
Multi-Agent Reinforcement Learning for Intrusion Detection: A case study and evaluation
Artificial Intelligence Group. Computer Sciences, University of York
In this seminar I will present an architecture of distributed sensor and decision agents that learn how to identify normal and abnormal states of the network using Reinforcement Learning (RL). Sensor agents extract network state information using tile-coding as a function approximation technique and send communication signals in the form of actions to decision agents. These in turn generate actions in the form of alarms to the network operator. By means of an on-line process, sensor and decision agents learn the semantics of the communication actions without any previous knowledge. In this presentation I will describe the learning process, the operation of the agent architecture and the evaluation results of our research work.
The presentation is here:
And a video of a Denial of Service Attack. Disclaimer: It may be disturbing for certain audience (it contains cheesy music from ABBA)
Posted by
Arturo Servin
at
06:54
1 comments
Labels: Denial of Service, IT security
Friday, 17 August 2007
A worm that strikes back
The last August 9th the REN-ISAC from the University of Indiana warned the academic community about the Storm Worm infected machines. After scanned, machines that are infected strike back with a flood DoS attack to the source of the scanning. The process seems to be automated according to the note.
Although the warning was issued to universities in U.S. I am sure that it will also affect to other universities and enterprises that have the scanning of hosts as one of their security policies.
More notes:
Information Week
The Register
Posted by
Arturo Servin
at
02:06
0
comments
Labels: DDoS, Denial of Service, Distributed Denial of Service, IT security
Friday, 10 August 2007
Spock or Spooky
This has nothing to do with my research, but any way it was a little bit amusing and worrisome to do some research about this topic. Few weeks ago I knew about Spock, a site for searching people. I was eager to jump in and to test what it was about (I did something similar for LinkedIn, Facebook, Myspace, etc. sometime ago) but then I thought. Even that someone offered me an invitation I stopped and I wonder. Do I really want all my personal data to be in just one place?
I mean, my data is there around my blogs, my website, my profile in I do not how many places. You just need to do some Google research to find my contacts details and some information about me. So, is there any difference between “google” me or search about me in Spock? Well, there is. I am not in Spock. Nice, isn’t it?
Well, but someday for sure I will, so, there will be any difference then? I think yes, while searching about people with Yahoo, Google or any other search engine you have to go around several pages to get all the data, while in Spock, you get it with just one or two clicks (depending how common is the name you are looking for). The implications are so great (I am been sarcastic if you haven’t noticed it), you can have all the need to make some online frauds, crack passwords, stole identities, etc. The possibilities are unlimited. I am being paranoiac, yeah, may be. In the other side, may be hackers will not use it any way, today is a little bit slow and online scammers rely in better applications than Spock to profile people (just read this). So, in the end I think that it will be very helpful to track some of your old friends, colleagues and classmates. And why not, to amuse you a little bit finding curious details of people that share the same name than your friends or best, to know details that you did not know about your friends. Just to mention I learn Zodiac Signs, weird hobbies, sexual interests, trips, past relations, etc. Every bit of information that is there but they did not share with you, you just need to dig a little to find it.
Until today, if you are trying to find some friends to get in touch, better use other methods such as Google. The database of Spock is still very small. Finally, the concept is not new. There are some other sites that do the same. The thing with Spock is that the marketing played and important role to bring it to the spot light.
Posted by
Arturo Servin
at
03:50
0
comments
Labels: IT security, search engines
Friday, 20 July 2007
True Random Generator Service
It is based on the " 'Quantum Random Bit Generator' (QRBG121), which is a fast non-deterministic random bit (number) generator whose randomness relies on intrinsic randomness of the quantum physical process of photonic emission in semiconductors and subsequent detection by photoelectric effect".
Why is this good? well because software cannot generate real random numbers, they just can generate pseudo random numbers.
Posted by
Arturo Servin
at
07:33
0
comments
Labels: IT security
Friday, 8 June 2007
Spammers using DDoS attacks
I read in a post in the SANS website that ansti-spam groups websites are under a DDoS attack. It is interesting the point of view of the post's author about seeing this as a desperate action from the spammers groups.
Posted by
Arturo Servin
at
01:27
0
comments
Labels: DDoS, Denial of Service, Distributed Denial of Service, IT security
Thursday, 24 May 2007
P2P networks used to launch DDoS attacks
I read a pair of notes about P2P networks (using DC++) hijacked to create botnets. The problem is caused by a vulnerability in the code of the P2P software that allows the injection of malicious code. The compromised host can be used to launch DDoS attacks.
Netcraft
Net-security
Posted by
Arturo Servin
at
05:33
0
comments
Labels: computer networks, DDoS, Denial of Service, Distributed Denial of Service, IT security, p2p
Wednesday, 23 May 2007
Some Security Tools
In the ISC SANS website, Jim Clausing publish a list of tools to capture, analyze, generate, modify and replay packets (the note does not mention "analyze but I think some of the tools cab be used to do it)
I wonder why are not there tools such as tcpreplay and vomit (used in Voice over IP). For more information about security tools a good resource is secure.org.
To use secure linux distros I would recommend Backtrack (based on slackware) and S-T-D (based on Kanoppix).
-as
Posted by
Arturo Servin
at
03:44
0
comments
Labels: IT security, tools
Distributed Denial of Service (DDoS) Attacks are Back
Yes, the Distributed Denial of Service (DDoS) Attacks are not in the past as pointed by Symantec's Yazan Gable in the enterprise blog. Some examples after his comments:
Finnish Website prey of DoS
DDoS/DoS to myBulgaria.info
Computer Terrorism For Sale
And that is not at all. Yesterday the British's Daily Telegraph website was knocked out by a DDoS (the note). In my opinion the more critical event was the apparent Russian's Cyber Attack against Estonia's network infrastructure some days ago. There are not yet enough information to clarify the incident but it would not be the first time that hackers from different countries attack each other after some political events (China v.s Taiwan). This remind me the comments of Professor Dorothy Denning in her book Information Warfare and Security. (Professor Denning was one of the first research works on Intrusion Detection Systems (IDS), her paper).
My opinion is that DDoS will be there no matter what security companies say. While the motivation exists, the problem will remain.
-as
Posted by
Arturo Servin
at
03:10
0
comments
Labels: DDoS, Denial of Service, Distributed Denial of Service, IT security