Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    US Government Botnet Report Warns About Lack of Security Tool Use

    Written by

    Sean Michael Kerner
    Published May 31, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Botnets and automated distributed threats have been a growing problem in recent years. In a report to the president that was publicly released on May 30, the U.S. Department of Commerce and the Department of Homeland Security detailed the status of botnet threats and provided direction on how to improve resiliency.

      The 51-page report comes a year after President Trump issued an executive order on strengthening the cyber-security of federal networks and critical infrastructure. As part of that order, there was a mandate to determine the risk and resiliency to U.S. infrastructure from botnets and automated distributed attacks. Among the key findings in the report is that existing tools to help improve defenses are not being used.

      “While there remains room for improvement, the tools, processes, and practices required to significantly enhance the resilience of the Internet and communications ecosystem are widely available, and are routinely applied in selected market sectors,” the report stated. “However, they are not part of common practices for product development and deployment in many other sectors for a variety of reasons, including (but not limited to) lack of awareness, cost avoidance, insufficient technical expertise, and lack of market incentives.”

      The report also determined that market incentives for product manufacturers are not aligned with the goal of reducing automated threats. According to the report, the goal of many vendors is to minimize cost and time to market, rather than to build in security.

      Industry Reaction

      Akamai Chief Security Officer Andy Ellis said he wasn’t surprised by the findings in the report, though he did call out a few of the conclusions.

      “The most notable is that the report acknowledges a lack of standards for safety and security in the IoT [internet of things] world,” Ellis told eWEEK.

      While the report noted that tools do exist to help mitigate some of the risks associated with botnets and automated distributed attacks, it also states that there are some gaps in the landscape. Ellis said that the cyber-security landscape can be confusing, which could be a cause for the perceived gaps in the marketplace.

      “For enterprises, it isn’t always clear what your best moves are, both from using vendors, as well as the parts of defense that an enterprise needs to own in their own right,” Ellis said. “I think the call for a framework is likely helpful here, although we should all be wary about proposing a one-size-fits-all model for DDoS defense.”

      Reid Tatoris, vice president of product marketing and outreach at Distil Networks, agrees with the report’s finding that tools exist that aren’t being utilized. He added, however, that there is also a gap in the way that some organizations think about the problem of automated distributed attacks.

      “Most people think about putting a solution in place to stop bot attacks, but advanced attackers constantly shift their attack vectors and methods,” Tatoris told eWEEK. “The mindset should be more focused on how to respond to ongoing threats, which means putting a flexible system in place that can stop current attacks and also detect and respond to new threats that evolve over time.”

      Srinivas Kumar, vice president of engineering at Mocana, calls the report is timely, particularly on the heels of the recent disclosure of the VPNFilter malware in networking equipment. Kumar noted that botnets present very real threats in IoT across a variety of domains, as detailed in the report.

      “While this report offers a variety of policy recommendations for action, perhaps the most important recommendations are those focused on promoting and incentivizing innovation,” Kumar told eWEEK. “The botnet threat landscape is one where hackers are proven to think and adapt faster than bureaucrats.” 

      Kumar added that implementing effective countermeasures against blind spots and addressing the threat of botnets require a paradigm shift in policy, process and technology that focuses on protection and prevention within the devices and systems of devices themselves.

      Georgia Weidman, founder and CTO of Shevirah, commented that while cyber-security awareness is part of the problem, there are technical limitations as well. She noted that for years much of security technology was focused on the network perimeter, which is no longer where all attacks come from.

      “With most of our budget sitting at the traditional perimeter, we are of course going to miss compromises originating from and DDoS traffic using these myriad alternative communication methods, such as a mobile modem that bypasses the perimeter or even close range communication methods such as Bluetooth or near-field communication if an attacker or his hardware is nearby, Weidman said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×