Terror has returned. Not just in Boston but throughout the great communications networks that power the world’s commerce and infrastructure. Large global services are constantly under siege by criminals looking to accomplish a variety of missions – knocking services offline, disrupting the financial ecosystem, theft, and political motives, just to name a few.
In America, criminals have launched Distributed Denial of Service (DDoS) attacks against major companies like NBC and Charles Schwab. They even hacked the Associated Press’s Twitter account and announced explosions at the White House. The stock market fell 100 points before recovering a few minutes later.
The DDoS epidemic has resulted in more than 200 attacks on U.S. financial institutions since September. As investigators dig into these attacks, they have uncovered “botnets” – swarms of infected computers that do whatever their criminal masters command. The criminals load an attack script to their army of infected computers, and at the appointed time, command their computer troops to log into the same website, rendering it inaccessible to actual customers.
Blocking these attacks used to be simpler when one attack came from one computer. Today’s DDoS attacks enlist so many attacking computers that it’s nearly impossible to stop them. A recent DDoS attack involved nearly 50,000 Internet addresses, generated more than 17 million login attempts measured in gigabytes per second (Gbps). Attacks above 10 Gbps and even 20 Gbps now occur multiple times per day, according to Arbor Networks’ first quarter ATLAS report.
These complex, synchronized attacks rely on compromised hosts collected using well-known flaws in our use of the Internet – most frequently related to poorly-secured services, unpatched workstations, limited application of best practices, and lack of attention to system logs. The targets may change, but the tactics remain largely the same.
Making It Easy For Them
Unfortunately, we make these attacks easy. Many home users have a tendency to keep using the same passwords over and over. In fact, a recent survey of security professionals revealed that 60 percent reused their passwords. For the criminal, that means cracking one user ID/password combination can open access to dozens of websites, servers and databases.
Another chink in our security armor is our willingness to spill the details of our lives on social media. A clever criminal need only comb LinkedIn or Facebook to find many of the details they need to construct a spearphishing attack. After all – employer name, year of service, position held, recent triumphs – it’s all there to develop into a convincing ruse to breach a company’s security perimeter.
More damaging than any of this is the public’s willingness to answer suspicious emails. Far too many of us have unintentionally opened links or attachments contained in email with such subject lines as:
- “Your account has been limited until we hear from you”
- “LogMeIn Notification – Software update required”
- “Online Alert: 2 suspicious login attempts!”
With the click of a mouse, we can tear a hole into our carefully-designed security perimeter and allow a computer virus to be installed.
Even so, it’s possible to prevent the computer virus from doing maximum damage. There are many ways to protect computers from web “filters” to automated software patching. Unfortunately, many computer users find these features so annoying, they disable or disregard them. One of the best protections – system warnings that the author of an application can’t be verified – gets bypassed every day.
User education has become a critical component in protecting ourselves from cybercrime. How else can we keep users aware of the threats, protections available, and best practices?
One of the greatest mistakes we make in the security field is to assume that someone else will protect us from cybercrime. Instead, we need to see ourselves as integral nodes in a security network dedicated to promote and maintain security. When one node fails, the network fails.
Organizations like Financial Services Information Sharing and Analysis Center (FS-ISAC) are promoting this concept by providing a forum for security professionals to share alerts, updates and countermeasures. This forum needs to be expanded to a much larger universe of computer users – the non-professionals who fall victim to these attacks.
But more importantly, the non-professionals need to take their own security seriously enough to take action to protect themselves. For that to happen, the threat of cybercrime will have to rise to the consumers’ boiling point. As we can see from the continuing stream of cyber-attacks, it hasn’t happened yet.
Robert Bessel is an account executive for Avon, Conn.-based COCC Inc.





