Security specialist Andreas Antonopoulos likes to talk about the “darknet” – the shadowy network of malware applications that operate at a layer above the traditional Internet. Encompassing everything from peer-to-peer applications to instant messaging and VoIP vulnerabilities and distributed denial-of-service attacks, the darknet poses a greater threat to companies than is commonly assumed.
At a recent conference on IP security, Carl Landwehr, program director for the National Science Foundation’s CyberTrust program, pointed out that as of last year, CERT has ceased publishing the number of known security incidents because there are simply too many to count. The number of attacks skyrocketed from hundreds per year in the 1990s to 137,529 in 2003 (the last year in which attacks were reported).
Landwehr further noted that while a significant percentage of these attacks are “bad guy vs. bad guy” – disgruntled hackers waging war against each other – there’s a worrisome increase in the number of for-profit distributed DoS attacks. Essentially what happens in this case is that a hacker launches a distributed DoS attack against a victim (financial services firms and online casinos are favorite targets) and demands money to stop. This has happened with increasing frequency over the past several months, including one recent incident in which a large U.S. consumer bank went offline for several hours.
The amount of peer-to-peer traffic has climbed significantly. Depending on whose statistics you believe, anywhere from 30% to 70% of traffic comprises peer-to-peer. While peer-to-peer is not necessarily illegal or even inappropriate – commercial peer-to-peer applications for purposes such as corporate data sharing are on the rise – if unchecked, it can swamp an enterprise network. Moreover, if the peer-to-peer application is being used for the transfer of copyrighted content, its mere presence on a corporate network can expose the company to legal liability.
Organizations need a multi-pronged approach to address these threats. Start by taking distributed DoS and related attacks seriously:
Investigate protective measures . Network providers such as AT&T offer distributed DoS protection services that function by detecting a distributed DoS attack in progress and using standard routing protocols to divert traffic to network-based “scrubbers” that eliminate most of the attack.
Diversify your Internet connectivity . As with many security measures, diversity is one of the best protections. Equinix offers Equinix Direct, a service that lets customers quickly and easily diversify their Internet connections.
Keep track of what’s on your network . Most companies have no idea what’s really on their network (although most think they do). FaceTime and Akonix have both introduced tools that let IT executives track peer-to-peer and IM vulnerabilities. FaceTime also has introduced FaceTime Instant Response Security Team, which includes tools and best practices to assess vulnerabilities.
- Educate yourself . There’s a lot of solid literature about darknets and how to protect against them. A good source for background on distributed DoS is at Washington University.




