Automated worms account for 90% of hack activity.
endif; ?>With their automated, rapid propagation mechanisms, worms account for at least 90% of the attacks, in general, systematically scanning and biting in sync.
Between the early hours of July 10 and midnight July 23, the network supporting Tel Aviv University was scanned for open ports 96,000 times and withstood a barrage of 82,000 hackers from 99 countries returning to those seemingly open ports to see if they could wreak a little havoc.
So do those statistics make it a bad couple of weeks for university IT managers working to keep unwanted Internet visitors at bay?
Unfortunately, it’s more like business as usual, says Oded Comay, CTO of ForeScout Technologies , whose ActiveScout intrusion-prevention technology helps pinpoint attempts and prevent attacks on this network that consists of more than 10,000 nodes, owns 128,000 public IP addresses and maintains a 100M bit/sec link to the Internet.
At least it’s business as usual these days, Comay says, because of the rise of highly automated attacks and computer worms that wiggle their way into corporate networks at lightning speeds.
Operating on the assumption that hackers do reconnaissance before attacking, the ActiveScout sensor sits outside the university’s primary firewall and watches incoming traffic for suspicious network probes and scans. When it identifies reconnaissance activity, it feeds the scanner in question counterfeit information, such as false resources, services, ports and IP addresses. If that same attacker tries to exploit the counterfeit information, ActiveScout denies access to the network.
I scan, therefore I attack
Except for a one-day blip in User Datagram Protocol (UDP ) traffic, there was a 96.3% match between scans and identified attackers or, in ActiveScout terms, bites. In other words, virtually every scan was followed at some point in time by an attack from the same source.
The reason is worms. Because of their automated, rapid propagation mechanisms, worms account for at least 90% of the attacks, in general, systematically scanning and biting in sync. If you take the top geographical offenders in our sample, you can further document that the large number of attacks coming out of China and the U.S. likely are automated.
According to the ActiveScout data, these worms propagate too quickly, and the time lapse between the scan and the bite is too minuscule to have been completely changed by a human. Worm activity also tends to be repetitive – they look for the same ports and bite on those ports on a mass scale.
According to ActiveScout officials who’ve been correlating data from multiple customer installations for more than a year, if you ignore the worm activity, you will see a scan-to-attack ratio of about 30%. This means that out of 10 scanners, three will return and actually bite. Differentiating the real hackers from the folks just playing with scripts for fun goes a long way in terms of your ability to filter through the Internet background noise to find the real threats.
Any port in the storm
Topping the list of scanning methods used against the university’s network are attackers looking for open ports. In fact, port-scanning accounts for 96% of all the network scans. Next is the UDP service scan (3.7% of scans conducted). Scan types falling into that last 0.3% include scans looking for username and passwords, NetBIOS Domain logon information and SNMP management data.
However, it’s important to note that the university goes to great lengths to sidestep worm attacks and huge amounts of network traffic facilitated by NetBIOS vulnerabilities, which potentially could infect all Windows-based machines. The university asked its ISP to filter all NetBIOS traffic before sending traffic over the university’s link so the relatively low numbers for NetBIOS scans – only 100 in all – is a bit skewed.
To provide some context regarding just how big a role NetBIOS scans can play on a network, we tapped into a second ForeScout node protecting a midsize virtual company in California that sports 255 public IP addresses and a T-1 link to the Internet. The top five scans were in the same order as exhibited in our Israeli sample, but the percentages were more spread out. Port scans amounted to 50%, UDP scans, 20%, and both NetBIOS and username and password scans, 15% each.
Six months ago on this node, port scans and NetBIOS scans comprised the bulk of the activity, 56% and 43%, respectively. But it’s also important to note that the sheer number of scans that hit this node grew by 260% between January and July.
What network services are they gunning for?
The ActiveScout also tracks the top services hackers are looking to influence in terms of the combined number of scans and bites, referred to as “attack events.”
On the university’s network, hackers overwhelmingly are looking to meddle in the Web page transfer services running on the university’s Web servers across TCP Port 80. Second are Windows-based network services with hackers trying to get at them via Ports 135, 139 and 445, where they can attack Microsoft’s DCE locator service, file and print services, and SMB over TCP transport services, respectively.
Other services of note are FTP services running over Port 21 that if hacked would let intruders store illegal MP3 files, for example; Squid proxy services running over Port 3128 that if compromised could be used as a spam relay; and Microsoft SQL Servers running on Port 1433. Port 1433 was big news when MS-SQL Slammer hit in January, but because the university still is seeing noticeable scans hitting that port, indications are that there are still SQL worms out there looking – and likely finding – unpatched machines and attacking them.
Roy Rotem of ForeScout Technologies contributed to this story.




