Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Mob Stoppers

    Written by

    eWEEK EDITORS
    Published July 2, 2001
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      One the most aggravating internet security threats today is a distributed denial-of-service attack — a flood of bogus network traffic that can effectively shut down a Web site. Far from going away, the phenomenon is evolving in different permutations, but new tools are emerging to help Internet administrators fight this vexing problem.

      DDOS attacks are the Internet equivalent of someone placing thousands of crank phone calls per second to your switchboard. Whatever the juvenile psychology that lies behind them, DDOS attacks have succeeded in felling the biggest sites on the Web, including those of Microsoft, Yahoo! and, more recently, the Computer Emergency Response Team Coordination Center at Carnegie Mellon University.

      The conventional wisdom among security experts has been that such attacks are, at best, a chronic nuisance — and at worst, impossible to prevent completely, since they are unpredictable and are often difficult to distinguish from legitimate traffic. DDOS attacks use distributed “zombies” — computers that have been planted with an unauthorized piece of packet-generating code — to fire billions of packets at a site simultaneously, chewing up its available bandwidth and overwhelming its servers.

      “Its not possible to prevent them,” says Stefan Savage, chief scientist at Asta Networks, which sells a system of network devices for detecting denial-of-service attacks. “There are a whole set of industry guidelines for security that everyone should adhere to, but ultimately, people are going to take over machines and theyre going to launch these attacks.”

      But Asta and each of the vendors in the growing anti-DDOS category say that their products or services can stop DDOS attacks before they cause significant outages. Other companies in this space include Mazu Networks, which last month launched its TrafficMaster system to quickly identify and reduce the impact of such attacks, and Arbor Networks, which offers a service to detect attacks and filter out DDOS traffic.

      Captus Networks has developed a family of networking devices, called CaptIO, that the company claims can detect and stop a DDOS attack in less than a second. The CaptIO system, which Captus says adds just 20 milliseconds of latency to network traffic and can handle gigabit-per-second throughput, automatically detects DDOS attacks in progress and is able to enforce on-the-fly policies to throttle back specific traffic flows. In addition, the Captus system can detect outbound traffic generated by zombies in a companys network that are being used as part of a DDOS attack against another site.

      Because most DDOS attacks last no longer than 20 minutes, a dynamic, automated defense is the only way to successfully defend against them, says Richard Helgeson, Captus president and CEO. “Youre never going to have enough people to look at all the traffic and eliminate the false positives generated by intrusion detection systems,” Helgeson says.

      Can these new technologies really solve the problem? One recent victim of a DDOS attack is skeptical.

      “Theres a lot of snake oil out there now,” says Steve Gibson, an independent software developer whose Gibson Research Corp. site, www.grc.com, was on the receiving end of several DDOS attacks in May. “There are a lot of companies saying: We have these products that can stop denial-of-service attacks. But they cant. There isnt a solution.”

      But even though such DDOS attacks are not fully preventable, their effects can definitely be mitigated, says Bob Lonadier, director of security strategies at Hurwitz Group. “Were seeing a movement away from stopping the attacks, to incorporating them under the umbrella of overall threat management,” Lonadier says. “You have to treat a denial-of-service attack as a threat, like viruses or any other threats to your security.”

      Now, however, a different problem with DDOS is emerging: the expense of the massive amounts of bandwidth consumed by such attacks. In fact, says Mazu CEO Phil London, a new kind of DDOS attack is designed not to cripple a Web site, but to fly under the radar in order to degrade its performance. “These attacks do have significant economic impact,” London says. “Without an ability to detect and mitigate those, you overprovision your network and buy more bandwidth. Unfortunately, its easy to get into an arms race like that with a hacker.”

      Some Web hosting providers already take DDOS attacks into consideration. For example, Rackspace Managed Hosting has a policy of waiving charges for additional bandwidth used by a denial-of-service attack, says Richard Yoo, chief technology officer at Rackspace.

      The larger issue surrounding DDOS attacks, Lonadier says, is that neither service providers nor their customers have taken ownership of the problem. “Right now,” he says, “theres just massive finger-pointing.”

      eWEEK EDITORS
      eWEEK EDITORS
      eWeek editors publish top thought leaders and leading experts in emerging technology across a wide variety of Enterprise B2B sectors. Our focus is providing actionable information for today’s technology decision makers.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×