The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label ddos. Tampilkan semua postingan
Tampilkan postingan dengan label ddos. Tampilkan semua postingan

Kamis, 10 Januari 2013

No Proof That Iran Is Behind U.S. Bank Attacks

A recent New York Times article reported that the U.S. government was convinced that the government of Iran was responsible for DDoS attacks against U.S. banks. No specific names of U.S. officials were mentioned which is troubling for several reasons:
  1. Government policy makers and administration officials are generally not very astute about the complexities of cyber attacks, incident response, and attribution. 
  2. The article's authors failed to interview any of the multiple cyber security experts who disagree with the sources quoted and/or referred to in the article.
  3. The reasons given by the Times' sources didn't exclude other possibilities besides the government of Iran.
On the other hand, multiple informed, authoritative sources have expressed skepticism about these attacks being state-sponsored, let alone by Tehran. Here are two authorities who were quoted in this Mashable article "Is Iran Behind A Wave Of Cyber Attacks Against U.S. Banks?":
Roel Schouwenberg, senior researcher at Kaspersky Labs (which identified several recent cyberattacks against Iran), didn't confirm or deny the attacks' origins. However, he doesn't believe the attacks are so complicated they must be the work of a government. 
“We can confirm that the attacks being reported are happening; however, the malware being used, known as ItsOKNoProblemBro, is far from sophisticated," wrote Schouwenberg in an e-mail. "It's really rather simple. It’s also only one part of the puzzle but it seems to be effective, which is all that matters to the attackers. Going strictly by the publicly known technical details, we don't see enough evidence that would categorize this operation as something only a nation-state sponsored actor could pull off.” 
Claudio Guarnieri, security researcher at Rapid7, agreed the complexity of the attacks is "disputable" and doesn't necessarily mean a government is behind them. 
"The malicious code involved is effective but very simple," wrote Guarnieri. "The link with state-sponsored entities could be justified by the fact that there is no direct gain for the attackers besides the disruption of the targets' operations. However, considering that there is no obvious evidence and that it could potentially be the work of generic cybercriminals, it's hard to confirm it.”
Then there's Dancho Danchev's expertly written article "Dissecting 'Operation Ababil' - an OSINT Analysis" which cast doubt on who was actually behind Operation Ababil, my article "Fact-checking the Iranian DDoS Attacks Against US Banks", and Anthony Freed's article "Bank DDoS Attacks: Is it the Russian Mob, Iran, or a False Flag?"

The public statements made by this group sound more like an Anonymous operation than something run by paramilitary Basij members or the IRGC, who's responsible for Iran's offensive cyber operations. The group's announcement of an equation based on page views of the offending film to determine the duration of attacks against the banks is too clever by half to be an official strategy. And at least one announcement failed to use proper punctuation for the word "God" and "Prophet" when referring to Allah and Mohammad (the author used lower case "g" and "p" instead of capital letters):
"The table below shows the result of search for the movie that insulted the god, his prophet and Muslims:"
I can't imagine a devout Muslim forgetting to capitalize God or Prophet but remembering to capitalize Muslim. I can imagine that mistake being done by someone who was using religious outrage as a pretense to support a false flag operation with Iran as the victim.

Relations with Iran are already tense. What we don't need is an internationally respected newspaper like the New York Times adding fuel to the fire by putting their name behind a story that presents no evidence and no objective examination of the facts by actual authorities in threat research, forensics, and incident response. You guys can and should do a lot better.
Add to Cart View detail

Jumat, 28 September 2012

Fact-checking the Iranian DDoS Attacks Against US Banks

There's a boat-load of misinformation being dispensed by CNN and Bloomberg about the DDoS attacks targeting our largest U.S. banks. Since this involves erroneous quotes from certain cyber security executives along with a U.S. Senator, I think a little fact-checking is in order.

Bloomberg: "Cyber attacks on the biggest U.S. banks, including JPMorgan Chase & Co. (JPM) and Wells Fargo (WFC) & Co., have breached some of the nation’s most advanced computer defenses and exposed the vulnerability of its infrastructure, said cybersecurity specialists tracking the assaults."

FALSE. This was a Distributed Denial of Service (DDOS) attack. Nothing was "breached". The web servers which hosted the banks' online services were overwhelmed by "calls" and couldn't handle them all.

Bloomberg: "Such a sustained network attack ranks among the worst-case scenarios envisioned by the National Security Agency, according to the U.S. official, who asked not to be identified because he isn’t authorized to speak publicly."

FALSE. There's no one that I know at the NSA (past or present) who believes that customer inconvenience resulting from a DDOS attack against their bank's website is a "worst-case scenario". That's utterly ridiculous.

Bloomberg: "The initial planning for the assault pre-dated the video controversy, making it less likely that it inspired the attacks, according to (Dmitri) Alperovitch and (Rodney) Joffe, both of whom have been tracking the incidents. A significant amount of planning and preparation went into the attacks, they said. “The ground work was done to infect systems and produce an infrastructure capable of launching an attack when it was needed,” Joffe said."

CNN: "To get hold of all the servers necessary to launch such huge attacks, the organizers needed to plan for months, Alperovitch said. The servers had to be compromised and linked together into a network called a "botnet."

FALSE. This attack did not take months to plan for two reasons: 1) This was a crowd-sourced opt-in botnet commonly used in social activism (aka hacktivist) attacks, and 2) No one needs to create a botnet from scratch anymore. You can find them to rent on pretty much any hacker forum world-wide.

CNN: "Sen. Joe Lieberman, an Independent from Connecticut, said in a C-SPAN interview on Wednesday that he believed the attacks were launched by Iran.
"I don't believe these were just hackers who were skilled enough to cause disruption of the websites," he said. "I think this was done by Iran ... and I believe it was a response to the increasingly strong economic sanctions that the United States and our European allies have put on Iranian financial institutions."

BULLSHIT.  There are lots of good reasons for tensions to exist between Iran and the U.S. but this isn't one of them. If you read the excellent open source analysis done by Dancho Danchev you'll see that this was nothing more than Islamic activists protesting the "Innocence of Muslims" video.

Paste bin notice by Qassam Cyber Fighters group
If Senator Lieberman thought this would be a good opportunity to do some Iran-bashing in order to drum up support for his cyber security legislation, he mis-calculated. This statement by the Senator only serves to reinforce the feeling by many that Congress is out of touch with the problem and is in no position to create new cyber security controls or policies.
Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID