Distributed Denial-of-service, or #DDoS, is a persistent threat facing businesses of all types, regardless of geographic location or target market. DDoS tools are becoming easier to use, while the attacks themselves are becoming more complex—frequently combining many different methods in one assault. With attack data from the F5 Silverline Security Operations Center and incidents logged by the F5 Security Incident Response Team (SIRT), I start the clock to check out DDoS Attack Trends for #2020 and read the article.
Tuesday, June 29, 2021
2021 Application Protection Report: Of Ransom and Redemption
Now in its 4th year, the #F5Labs 2021 Application Protection Report (https://www.f5.com/labs/articles/thre...) is our effort to boil the application security risk landscape down to put the initiative back into the hands of defenders. We analyzed more than 700 data breaches from 2020. Peter Silva starts the clock for an extended edition of some the highlights from F5Labs 2021 #APR in this episode of 90 Seconds of Security.
Get your copy of the 2021 APRF5 SIRT’s Top Reported Security Incidents, 2018-2020
The F5 Security Incident Response Team helps customers tackle security incidents in real time. In 2020, we talked about what happened in the beginning of the pandemic based on #F5 #SIRT cases. Now we're looking back at all F5 SIRT cases from the beginning of 2018 to the end of 2020 and break down what changed and what didn’t in the cyberthreat landscape because of the pandemic. So, let’s start the clock to look at SIRT’s Top Reported Security Incidents, 2018-2020. Go to the full article
Saturday, December 26, 2020
How Cyber Attacks Changed During the Pandemic
#F5 SIRT reviewed all the reported security incidents from January through August 2020 to see how the pandemic changed the cyberthreat landscape. Hint: #DDoS attacks dominated the pandemic lockdown. Learn more: https://www.f5.com/labs/articles/threat-intelligence/how-cyber-attacks-changed-during-the-pandemic
So let’s start the clock to see How Cyber Attacks Changed During the #Pandemic.
Friday, November 6, 2020
Cloud Interconnection with F5 & Equinix
Learn how the simplified Interconnection Oriented Architecture (IOA) from #F5 and #Equinix helps IT departments solve the need for mobile and dispersed user access to their cloud infrastructure(s) in a multi-cloud environment.
Learn more: https://www.f5.com/services/resources/use-cases/a-secure-equinix-gateway-to-the-cloudThursday, September 26, 2019
90 Seconds of Security: F5 SIRTs Top Tip for Keeping Your BIG-IP and Your Network Secure
For more information about SIRT’s specialized service please visit: https://www.f5.com/sirt
Friday, August 30, 2019
90 Seconds of Security: F5 Security at Black Hat USA 2019
Tuesday, November 28, 2017
Mitigate L7 DDoS with BIG-IP ASM
We’ve logged into a BIG-IP ASM and navigated to Security>DDoS Protection>DDoS Profiles. In the General Settings of Application Security, we’ll activate an application DoS iRule event.
When the user requests a web application proxied by BIG-IP ASM, ASM will create a unique identifier or a Device ID. ASM will inject JavaScript to register each client device. You can see X-Device-ID: at the bottom.
And JavaScript incapable clients never make it through.
Now that the unit is ready, let’s enable some packet capture and take a go at that damn vulnerable web application.
Path for the log files is /var/log/ or /shared/log/…the PCAP folder is empty so let’s see the action.
Attack commence in 3-2-1. Some quick refreshes should do as our thresholds are low.
The first mitigation is Client Side Integrity Defense. The system issues a client-side integrity challenge that consumes client computation resources and slows down the attack. Next is Built-in Captcha. The third mitigation is Rate Limiting…
..then if they’re still not listening, you can instantly transform into a Honeypot.
The logs below show the IP address and the type of mitigation technique deployed. First Integrity, then Captcha, then Rate Limiting, then Honeypot if they don't stop. The traffic you recorded will be found in the, now populated, PCAP folders.
Thanks to F5 SE Artiom Lichtenstein for the demo video.
ps
Related:
Wednesday, November 1, 2017
Lightboard Lessons: What is DDoS?
ps
Related:
Wednesday, July 19, 2017
Lightboard Lessons: Attack Mitigation with F5 Silverline
ps
Tuesday, February 7, 2017
Security Trends in 2016: Securing the Internet of Things
And it’s not the only IoT botnet out there nor are these nasty botnets going away anytime soon. There’s a gold mine of unprotected devices out there waiting to either have their/your info stolen or be used to flood another website with traffic.
This is bound to compound in the years to come.
A recent Ponemon Institute report noted that an incredible 80% of IoT applications are not tested for vulnerabilities. Let’s try that again – only 20% of the IoT applications that we use daily are tested for vulnerabilities. There’s probably no indication or guarantee that the one you are using now has been tested.
Clearly a trend we saw in 2016, and seems to continue into 2017, is that people are focusing too much on the ‘things’ themselves and the coolness factor rather than the fact that anytime you connect something to the internet, you are potentially exposing yourself to thieves. There has been such a rush to get products to market and make some money off a new trend yet these same companies ignore or simply do not understand the potential security threats. This somewhat mimics the early days of internet connectivity when insecure PCs dialed up and were instantly inundated with worms, viruses and email spam. AV/FW software soon came along and intended to reduce those threats.
Today it’s a bit different but the cycle continues.
Back then you’d probably notice that your computer was acting funky, slowing down or malfunctioning since we interacted with it daily. Today, we typically do not spend every waking hour working with our IoT devices. They’re meant to function independently to grab data, make adjustments and alert us on a mobile app with limited human interaction. That’s the ‘smart’ part everyone talks about. But these botnets are smart themselves. With that, you may never know that your DVR is infected and allowing someone across the globe (or waiting at the nearest street corner) watch your every move.
Typical precautions we usually hear are actions like changing default passwords, not connecting it directly to the internet and updating the firmware to reduce the exposure. Software developers, too, need to plan and build in security from the onset rather than an afterthought. The security vs. usability conundrum that plagues many web applications extends to IoT applications also. But you wouldn’t, or I should say, shouldn’t deploy a financial application without properly testing it for vulnerabilities. There the risk is financial loss but with IoT and particularly medical/health devices the result can be deadly.
Mirai was just the beginning of the next wave of vulnerability exploitation. More chaos to come.
ps
Related:
- Rise of the Machines Report - Institute of Critical Infrastructure Technology (pdf)
- The Botnet that Broke the Internet Isn’t Going Away
- Mirai Strikeback - an iRule to kill IoT Bot Processes from your F5
- Security Sidebar: Regulating the Internet of Things
- Hotel ransomed by hackers as guests locked in rooms
- 80% of IoT apps not tested for vulnerabilities, report says
- Awesome IoT Hacks (Github)
- RSA 2017: The Internet of Things security threat
Thursday, February 2, 2017
What is DNS?
What is the Domain Name System (DNS)?
Imagine how difficult it would be to use the Internet if you had to remember dozens of number combinations to do anything. The Domain Name System (DNS) was created in 1983 to enable humans to easily identify all the computers, services, and resources connected to the Internet by name—instead of by Internet Protocol (IP) address, an increasingly difficult-to-memorize string of information. Think of all the website domain names you know off the top of your head and how hard it would be to memorize specific IP addresses for all those domain names. Think of DNS as the Internet's phone book. A DNS server translates the domain names you type into a browser, like www.f5.com, into an IP address (104.219.105.148), which allows your device to find the resource you're looking for on the Internet.DNS is a hierarchical distributed naming system for computers, services, or other resources connected to the Internet. It associates various information with domain names that are assigned to each of the participating DNS entries.
How DNS Works
The user types the address of the site (www.f5.com as an example) into the web browser. The browser has no clue where www.f5.com is, so it sends a request to the Local DNS Server (LDNS) to ask if it has a record for www.f5.com. If the LDNS does not have a record for that particular site, it begins a recursive search of the Internet domains to find out who owns www.f5.com.First, the LDNS contacts one of the Root DNS Servers, and the Root Server responds by telling the LDNS to contact the .com DNS Server. The LDNS then asks the .com DNS Server if it has a record for www.f5.com, and the .com DNS Server determines the owner of www.f5.com and returns a Name Server (NS) record for f5.com. Check out the diagram below:
DNS Importance
As arguably the primary technology enabling the Internet, DNS is also one of the most important components in networking infrastructure. In addition to delivering content and applications, DNS also manages a distributed and redundant architecture to ensure high availability and quality user response time—so it is critical to have an available, intelligent, secure, and scalable DNS infrastructure. If DNS fails, most web applications will fail to function properly. And DNS is a prime target for attack.The importance of a strong DNS foundation cannot be overstated. Without one, your customers may not be able to access your content and applications when they want to—and if they can't get what they want from you, they'll likely turn elsewhere.
Growing Pains
DNS is growing especially with mobile apps and IoT devices requiring name resolution. Add to that, organizations are experiencing rapid growth in terms of applications as well as the volume of traffic accessing those applications.In the last five years, the volume of DNS queries on for .com and .net addresses has more than doubled. More than 10 million domain names were added to the Internet in 2016 and future growth is expected to occur at an even faster pace as more cloud, mobile and IoT implementations are deployed.
Security Issues
If DNS is the backbone of the Internet—answering all the queries and resolving all the numbers so you can find your favorite sites—it is also one of the most vulnerable points in your network. Due to the crucial role it plays, DNS is a high-value security target. DNS DDoS attacks can flood your DNS servers to the point of failure or hijack the request and redirect requests to a malicious server. To prevent this, a distributed high-performing, secure DNS architecture and DNS offload capabilities must be integrated into the network.Generally, DNS servers and DNS cloud services can handle varying amounts of requests per second with the costs increasing as the queries-per-second increase.
To address DNS surges and DNS DDoS attacks, companies add more DNS servers, which are not really needed during normal business operations. This costly solution also often requires manual intervention for changes. In addition, traditional DNS servers require frequent maintenance and patching, primarily for new vulnerabilities.
The Traditional Solution
When looking for DNS solutions, many organizations select BIND (Berkeley Internet Naming Daemon), the Internet's original DNS resolver. Installed on approximately 80 percent of the world's DNS servers, BIND is an open-source project maintained by Internet Systems Consortium (ISC).Despite its popularity, BIND requires significant maintenance multiple times a year primarily due to vulnerabilities, patches, and upgrades. It can be downloaded freely, but needs servers (an additional cost, including support contracts) and an operating system. In addition, BIND typically scales to only 50,000 responses per second (RPS), making it vulnerable to both legitimate and malicious DNS surges.
Next Step
If you're ready to learn more or dig deeper into DNS, check out these more advanced articlesTuesday, March 8, 2016
The Roadblock for Malicious Traffic
In a business environment, security is all about risk: Assessment, analysis, management and mitigation. The many IT security trends like IoT, cloud, device proliferation, disappearing perimeter, and so forth are all potential risks to the business. To reduce their risk, organizations need to ensure they can scale to meet the global workforce’s and customer’s data demand; they need to secure their data from targeted attacks, unauthorized access, inadvertent leakage or to comply with regulatory rules; and they need to keep their operational infrastructure simple and efficient.
The BIG-IP platform offers the scale and capacity to meet the deluge, the full proxy security to protect the applications and infrastructure and the operational efficiency to consolidate functions within an application centric security model. The BIG-IP platform is a full proxy architecture – establishing a TCP connection with the client to the BIG-IP and a separate TCP connection from the BIG-IP to the resources themselves. It is able to apply policies on both ends, anywhere along the stack. This allows organizations to inspect, manipulate or simply drop traffic – on the way in or on the way out - if it does not adhere to the policy. Plus, iRules extensibility gives you the power to do almost anything with the traffic.
BIG-IP Advanced Firewall Manager (AFM) is a stateful, full-proxy, ICSA-certified firewall and brings additional network firewall capabilities at a fine granular level allowing administrators to easily protect their infrastructure and understand what types of attacks are infiltrating the network. Logging and reporting are built-in. BIG-IP AFM can be added to any BIG-IP platform and can help reduce those business risks.
Bringing together security and deep application fluency, BIG-IP AFM delivers the most effective network-level security for enterprises and service providers alike. Whether on-premises or in the cloud, BIG-IP AFM tracks the state of network sessions, maintains application awareness, and mitigates threats based on attack details that most traditional network firewalls simply do not have. It helps you respond to threats quickly and with a full understanding of your security posture. In addition, AFM protects your organization from the most aggressive DDoS attacks before they ever reach your data center.
F5 DevCentral has a whole AFM series coming your way over the next few weeks! The schedule includes:
- March 15th: Foundational / Provisioning – This will kick of the series, taking what John tackled in AFM Provisioning and Policy Building and fleshing out more of the finer details in provisioning and basic policy functionality.
- March 17th: Architectural Context – We’ll dive deep into the architecture to define global and local contexts, work through precedence decision trees, and introduce the programmability entrance points.
- March 22nd: Policy Building – Harder, stronger, balanced and more flexible policies to combat all those bad actors out there! Lessons learned and best practices will help you wield a more powerful weapon in the battle.
- March 24th: DDoS Capabilities: AFM shines with DDoS mitigation. You’ll see the many attack vectors handled auto-magically for you, as well as walk through some demos of attack mitigations in action.
- March 29th: Blacklisting Magic - As the title says...
- March 31st: IP Intelligence - Blocking bad actors at the core.
- April 5th: Attack Mitigation Approaches (zero-window / udp flood / Christmas tree / etc.) - We’ll take a look at some of these attacks and show you how to combat them.
- April 7th: Full stack protection – Where does AFM end and ASM begin? You’ll see how these two modules complement each other and provide synergistic protection for all layers of your application and delivery infrastructure.
- April 12th: iRules extensions - Programmability to help stop those tricky attacks.
- April 14th: DNS firewall deployments - We'll show you how to make one mighty powerful firewall for your DNS infrastructure.
ps
Monday, April 20, 2015
RSA2015 – Find F5
Sporting the crisp F5 ‘Defend the New Perimeter’ t-shirt, I show you how to find F5 booth 1515 at RSA 2015 in 17 paces or less. The theme this year is Change – Challenge today’s security thinking and with the mobile revolution, applications delivered from hybrid environments and the shifting perimeter, changing your security thinking today will help protect your business applications tomorrow.
ps
Related
| Connect with Peter: | Connect with F5: |
| |
Monday, March 2, 2015
MWC 2015 – Threats to Mobile Carrier Networks (feat George)
ps
Related
- Mobile World Congress 2015 - The Preview Video
- MWC 2015 - Find F5
- MWC 2015 – NFV for Service Providers (feat Yue)
- F5 at #MWC15
- F5 YouTube Channel
| Connect with Peter: | Connect with F5: |
| |
Wednesday, May 14, 2014
Uncle DDoS'd, Talking TVs and a Hug
Information security is one of those areas where a lot is always happening. From breaches to vulnerabilities to scams to anything else that's designed to store, protect or even attack and pilfer our sensitive information, information security encompasses a lot of things. A Three Ring Circus, Three Little Pigs, The Three Stooges and when three different stories grab my attention, well I just gotta share.
SCMagazine.com had an interesting story yesterday talking about how two servers designed to prevent DDoS attacks were, themselves, used in a DDoS attack. Incapsula reported that it had to fend off a sizable DDoS attack that was launched using high-capacity servers hijacked from a DDoS protection services provider. The attack itself was against an online gaming site and the attackers actually hijacked and commandeered two high capacity servers from a DDoS protection service provider to spearhead the attack. The service provider was so focused on incoming traffic, they had to be notified to take a look at the massive outgoing traffic being sent. While the DDoS protection market has grown with many outsourcing solutions, it is still a shared service. Remember the old tiered-hosting-separated-by-a-partition days? Even if you are not the target, you still might be caught up in it if your neighbor is.
Next up is security experts at NCC Group said SmartTVs with built-in microphones and storage can be turned into bugging devices by malware and used to record conversations. Not to mention remotely turning on the TV camera at will. They did need physical access to the TV to install the malware but as more TV apps get developed, it is conceivable that a malicious app could be downloaded to the TV for the same purpose. They demonstrated how they could capture 30 seconds of buffered mic audio but could have also manipulated more to use internal storage and send the audio files to an awaiting server. NCC engineers wanted to highlight the security shortcomings on the home front of the Internet of Things. Start to get used to no privacy in the privacy of your home.
And last but certainly not least, Thieves steal ID and credit card data with a hug. OK, I'm Hawaiian and we are a bunch of huggers so this is interesting. Apparently a Georgia woman was approached at a gas station by another woman begging for some money so she could put gas in her car. The kind, generous woman gave the crooked lady $20. With a full Oscar nominated performance, the crooked lady wept with joy and wanted to thank the generous one with a hug. Embrace ensued. So touched by the gesture, the man with the crooked lady got out of the car and also wanted to physically thank the Samaritan. The next morning she realized why they wanted to hug her when she discovered that $3000 was gone from her bank account. $2400 from a grocery store and another $200 plus from ATMs. The thieves got close so they could scan her for RFID enabled cards. She had her credit cards in her front pocket and was scanned during the not so loving embrace. Well that sucks. The cool thing is that the woman is not jaded and will continue to help others. Nice.
And to those I know: If we typically hug when we see each other, I promise won't be scanning your pockets.
ps
Related
- Hijacked anti-DDoS servers used to carry out massive DDoS attack
- F5 DDoS Protection
- Hey, does your Smart TV have a mic? Enjoy your surveillance, bro
- Your TV might be watching you
- The ABCs of the Internet of Things
- Thieves steal ID, credit card data with a hug
- Georgia Good Samaritan scammed by couple she helped
| Connect with Peter: | Connect with F5: |
| |
Thursday, April 24, 2014
A Decade of Breaches
Whales Not Included
Being from the Hawaiian Islands, the annual gathering of the Kohola (humpback whales) is always a spectacular view. They can get over half their body out of the water and administer a cannonball body slam splash like you've never seen before. Most of the internet thinks they breach to either see what's up (so to speak), let other whales know they are around (if the haunting squeal isn't doing it) and most common, to relieve the body of lice, parasites and barnacles.
While nature's breaches are unmatched, many internet security breaches are run of the mill leakages.
The Verizon 2014 Data Breach Investigation Report (DBIR) found that over the last 10 years, 92% of the 100,000 security incidents analyzed can be traced to nine basic attack patterns. The patterns identified are:
- Miscellaneous errors like sending an email to the wrong person
- Crimeware (malware aimed at gaining control of systems)
- Insider/privilege misuse
- Physical theft or loss
- Web app attacks
- Denial of service attacks
- Cyberespionage
- Point-of-sale intrusions
- Payment card skimmers
The really cool thing about the 9 attack patterns is that Verizon has also charted the frequency of incident classification patterns per industry vertical. For instance, in financial services 75% of the incidents come from web application attacks, DDoS and card skimming while retail, restaurants and hotels need to worry about point-of-sale intrusions. Utilities and manufacturing on the other hand get hit with cyber-espionage. Overall across all industries, only three threat patterns cover 72 percent of the security incidents in any industry.
Once again, no one is immune from a breach and while media coverage often focuses on the big whales, the bad guys are not targeting organizations because of who they are but because a vulnerability was found and the crooks decided to see if they could get more. This means that companies are not doing some of the basics to stay protected. For the 2014 analysis, there were 1,367 confirmed data breaches and 63,437 security incidents from 50 global companies.
For the most part, the fixes are fairly basic: Use strong authentication, patch vulnerabilities quickly and encrypt devices that contain sensitive information. I've barely scratched the surface of the report and highly suggest a through reading.
ps
Related
- Verizon 2014 Data Breach Investigations Report Identifies More Focused, Effective Way to Fight Cyberthreats
- Verizon Data Breach Investigations Report
- Verizon's data breach report: Point-of-sale, Web app attacks take center stage
- DBIR: Poor Patching, Weak Credentials Open Door To Data Breaches
- Bricks (Thru the Window) and Mortar (Rounds)
- Surfing the Surveys: Cloud, Security and those Pesky Breaches
- Targets of Opportunity
- Unplug Everything!
Photo: Protected Resources Division, Southwest Fisheries Science Center, La Jolla, California.
| Connect with Peter: | Connect with F5: |
| |
Tuesday, February 25, 2014
RSA 2014: DDoS Protection (feat Bocchino)
ps
Related
- RSA 2014: Find F5
- RSA 2014: Anti-Fraud Solution (feat DiMinico)
- RSA 2014: Secure Web Gateway (feat Moses)
- F5 at RSA 2014
- F5 Secure Web Gateway – Reference Architecture
- F5 Web Fraud Protection – Reference Architecture
- F5 Expands Synthesis Architecture with Advanced Web and Fraud Protection Services for Worry-Free Application and Internet Access
- F5 YouTube Channel
| Connect with Peter: | Connect with F5: |
| |






