(BUSINESS WIRE)--Damballa Inc., the company transforming the fight against cyber threats, today announced the discovery of a new botnet that offers pay-for-delivery Distributed Denial of Service (DDoS) attacks. The ‘IMDDOS’ Botnet, named after the commercial name on the botnet website, has grown to be one of the largest active global botnets in less than four months from initial testing. According to Damballa, the infected hosts used in the DDoS attacks have become unwitting participants in the botnet and are widespread. The vast majority of infected hosts are in China, with the United States being in the top 10 countries affected. Internet Service Providers (ISPs) worldwide were affected, including the majority of North American ISPs, and a number of major corporate networks are hosting bot agents for the IMDDOS Botnet.
“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting”
The IMDDOS Botnet offers a commercial service for delivering DDoS attacks against any desired target. Hosted in China, this publicly available service is available for lease to anyone willing to establish an online account, input the domain(s) they wish to attack, and pay for the service. Throughout the Damballa period of study, the botnet grew large very quickly. Following testing by the criminal operators in April 2010, it reached a production peak of activity with 25,000 unique Recursive DNS (RDNS) lookups per hour attempting to resolve to the botnet’s command-and-control (CnC) servers. Damballa is currently working with ISPs and law enforcement officials to contain and nullify the threat.
A 16-page analysis of the discovery can be viewed at: www.damballa.com/IMDDOS. This analysis includes details of the technical infrastructure of the botnet and associated malware as well as an animated illustration of the IMDDOS Botnet’s global growth and impact from early testing stage to peak activity rendered in hourly increments.
A Denial of Service (DoS) attack is a technique used to overwhelm a website/domain in an effort to reduce its responsiveness or completely eliminate its ability to respond to new connection attempts. DoS attacks have historically been used to ‘take down’ political sites, abuse sites, commercial business websites and even military command centers as part of a coordinated targeted campaign.
A DDoS attack utilizes multiple PCs or servers to initiate a coordinated attack against a targeted system. The more assets involved in the attack, the larger the flood of requests and data that can be targeted at the victim. To create a very large army of assets that can launch DDoS attacks, botnets are used to rally and command unwitting victim machines into participating in the attacks.
“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting,” stated Gunter Ollmann, vice president of research for Damballa. “The public website hosting the DDoS service offering, with various ‘plans’ and attack options, speaks to the ease with which anyone can leverage criminal infrastructure. The malware used is simplistic, yet it was successful in spreading rapidly. And while it appears to be primarily a DDoS delivery platform, the size of the botnet reached impressive proportions, certainly large enough to wreak major havoc on any victim organization should it be pointed in the right direction.”
This discovery was made possible due to a global array of Damballa sensors, which provide worldwide visibility into CnC activity, combined with the understanding and quantification of statistical heuristics that can explain, and most importantly, quickly detect, the malicious nature of this botnet operation. Damballa tracks thousands of botnet operators and their growing cache of botnets every day. Each criminal botnet building campaign is observed, analyzed, automatically catalogued and categorized using a sophisticated array of clustering and machine learning systems. As the criminal botnet operators attempt to grow the botnet, their investments and modifications to their CnC hosting infrastructure are tracked and used as markers for eventual attribution. Damballa customers benefit from this advanced knowledge of the threat, being alerted to the presence of the malware and being able to terminate the CnC communications.
“Botnets are recognized by industry experts as being the delivery mechanism of choice for the vast majority of today’s cyber threats that plague corporate and ISP networks,” said Val Rahmani, CEO of Damballa. “Botnets and other cyber threats are attacking corporate networks and service providers at an alarmingly high rate and are causing security teams around the world to reevaluate their security investments. Damballa leads the security industry in delivering solutions that detect and terminate botnets and cyber threats, and our research and product teams are constantly innovating and bringing more powerful and automated weapons to the war against cybercrime.”
-----
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Showing posts with label botnet. Show all posts
Showing posts with label botnet. Show all posts
Tuesday, September 14, 2010
Wednesday, July 28, 2010
FBI, Slovenian and Spanish Police Arrests Mariposa Botnet Creator, Operators
The FBI, in partnership with the Slovenian Criminal Police and the Spanish Guardia Civil, announced today significant developments in a two-year investigation of the creator and operators of the Mariposa Botnet. A botnet is a network of remote-controlled compromised computers.
The Mariposa Botnet was built with a computer virus known as “Butterfly Bot” and was used to steal passwords for websites and financial institutions. It stole computer users’ credit card and bank account information, launched denial of service attacks, and spread viruses. Industry experts estimated the Mariposa Botnet may have infected as many as 8 million to 12 million computers.
“In the last two years, the software used to create the Mariposa botnet was sold to hundreds of other criminals, making it one of the most notorious in the world,” said FBI Director Robert S. Mueller, III. “These cyber intrusions, thefts, and frauds undermine the integrity of the Internet and the businesses that rely on it; they also threaten the privacy and pocketbooks of all who use the Internet.”
In February, the Spanish Guardia Civil arrested three suspected Mariposa Botnet operators: “Netkairo,” “Jonyloleante,” and “Ostiator,” aka Florencio Carro Ruiz, Jonathan Pazos Rivera, and Juan Jose Bellido Rios. These individuals are being prosecuted in Spain for computer crimes.
Last week, the Slovenian Criminal Police identified and arrested the Mariposa Botnet’s suspected creator, a 23-year-old Slovenian citizen known as “Iserdo.” The work of the Slovenian and Spanish authorities was integral to this investigation.
FBI Cyber Division Assistant Director Gordon M. Snow said: “This case shows the value of strong partnerships among law enforcement agencies worldwide in the fight against cyber criminals. Cyber crime knows no boundaries, and without international collaboration, our efforts to dismantle these operations would be impossible. The FBI praises the work of our Slovenian and Spanish partners who worked closely with our agents in this case.”
In a statement, Slovenian Minister of the Interior Katarina Kresal and Director General Janko Gorsek, Slovenian Criminal Police, said: “We are glad to cooperate with the United States; the FBI’s assistance is invaluable and represents professional affirmation of our force. This case shows that cyber crime issues call for international police cooperation that shouldn’t be hindered by geographical borders. The FBI has demonstrated a high level of collaboration in which our countries were equal partners, which was crucial for the success of the investigation and reducing the threat on a global level. This partnership serves as a solid basis for future cooperation.”
Maj. Juan Salom, commander of the Guardia Civil’s Cyber Crime Division, noted: “The Mariposa case showed how the coordinated and joint actions of different international police forces, along with the efforts of the Internet security industry, have been able to face the global threat of cyber crime,” he said. “The cyber kingpins know that they are not invincible anymore because the global efforts of the FBI, Slovenian Criminal Police, and Spanish Guardia Civil have shown that it doesn’t matter where or how they try to hide, they will be located and prosecuted.”
From 2008 to 2010, the Slovenian citizen created “Butterfly Bot” and sold it to other criminals worldwide. In turn, these criminals developed networks of infected computers—botnets—and the Mariposa variety from Spain was the most notorious and largest. In addition to selling the Butterfly Bot program, the Slovenian citizen developed customized versions for certain customers and created and sold plug-ins (add-ons) to augment the botnet’s features and functionality.
This case is significant because it targeted not only the operators of the botnet but also the creator of the malicious software that was used to build and operate it. The success of this investigation was made possible because of the skill, professionalism, and commitment of the Slovenian Criminal Police’s Cyber Crime Division and the Spanish Guardia Civil’s Computer Crimes Group.
The FBI conducted this investigation with the assistance of the United States Attorney’s Office, District of Hawaii, and the Department of Justice’s Computer Crime and Intellectual Property Section, Office of International Affairs, and the Botnet Threat Focus Cell. The FBI also received invaluable assistance from the Mariposa Working Group.
------
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
The Mariposa Botnet was built with a computer virus known as “Butterfly Bot” and was used to steal passwords for websites and financial institutions. It stole computer users’ credit card and bank account information, launched denial of service attacks, and spread viruses. Industry experts estimated the Mariposa Botnet may have infected as many as 8 million to 12 million computers.
“In the last two years, the software used to create the Mariposa botnet was sold to hundreds of other criminals, making it one of the most notorious in the world,” said FBI Director Robert S. Mueller, III. “These cyber intrusions, thefts, and frauds undermine the integrity of the Internet and the businesses that rely on it; they also threaten the privacy and pocketbooks of all who use the Internet.”
In February, the Spanish Guardia Civil arrested three suspected Mariposa Botnet operators: “Netkairo,” “Jonyloleante,” and “Ostiator,” aka Florencio Carro Ruiz, Jonathan Pazos Rivera, and Juan Jose Bellido Rios. These individuals are being prosecuted in Spain for computer crimes.
Last week, the Slovenian Criminal Police identified and arrested the Mariposa Botnet’s suspected creator, a 23-year-old Slovenian citizen known as “Iserdo.” The work of the Slovenian and Spanish authorities was integral to this investigation.
FBI Cyber Division Assistant Director Gordon M. Snow said: “This case shows the value of strong partnerships among law enforcement agencies worldwide in the fight against cyber criminals. Cyber crime knows no boundaries, and without international collaboration, our efforts to dismantle these operations would be impossible. The FBI praises the work of our Slovenian and Spanish partners who worked closely with our agents in this case.”
In a statement, Slovenian Minister of the Interior Katarina Kresal and Director General Janko Gorsek, Slovenian Criminal Police, said: “We are glad to cooperate with the United States; the FBI’s assistance is invaluable and represents professional affirmation of our force. This case shows that cyber crime issues call for international police cooperation that shouldn’t be hindered by geographical borders. The FBI has demonstrated a high level of collaboration in which our countries were equal partners, which was crucial for the success of the investigation and reducing the threat on a global level. This partnership serves as a solid basis for future cooperation.”
Maj. Juan Salom, commander of the Guardia Civil’s Cyber Crime Division, noted: “The Mariposa case showed how the coordinated and joint actions of different international police forces, along with the efforts of the Internet security industry, have been able to face the global threat of cyber crime,” he said. “The cyber kingpins know that they are not invincible anymore because the global efforts of the FBI, Slovenian Criminal Police, and Spanish Guardia Civil have shown that it doesn’t matter where or how they try to hide, they will be located and prosecuted.”
From 2008 to 2010, the Slovenian citizen created “Butterfly Bot” and sold it to other criminals worldwide. In turn, these criminals developed networks of infected computers—botnets—and the Mariposa variety from Spain was the most notorious and largest. In addition to selling the Butterfly Bot program, the Slovenian citizen developed customized versions for certain customers and created and sold plug-ins (add-ons) to augment the botnet’s features and functionality.
This case is significant because it targeted not only the operators of the botnet but also the creator of the malicious software that was used to build and operate it. The success of this investigation was made possible because of the skill, professionalism, and commitment of the Slovenian Criminal Police’s Cyber Crime Division and the Spanish Guardia Civil’s Computer Crimes Group.
The FBI conducted this investigation with the assistance of the United States Attorney’s Office, District of Hawaii, and the Department of Justice’s Computer Crime and Intellectual Property Section, Office of International Affairs, and the Botnet Threat Focus Cell. The FBI also received invaluable assistance from the Mariposa Working Group.
------
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Wednesday, April 22, 2009
Finjan Discovers a Network of 1.9 Million Malware-Infected Computers Controlled by Cybercriminals - Corporate and Government Computers are Included

/PRNewswire/ -- Finjan Inc., a leader in secure web gateway products and the provider of unified web security solutions for the enterprise market, today announced that Finjan's Malicious Code Research Center (MCRC) has discovered a network of 1.9 million malware-infected computers. Corporate, government and consumer computers around the world were infected by the malware.
This discovery is part of a research conducted by MCRC when investigating command and control servers operated by cybercriminals. The cybercrime server has been in use since February 2009, is hosted in the Ukraine and is controlled by a cybergang of 6 people. These cybercriminals established a vast affiliation network across the Web to successfully distribute and operate their malware install-base. They compromised computers in 77 government-owned domains (.gov) from the US, UK and various other countries.
The malware is remotely controlled by the cybercriminals, enabling them to instruct the malware to execute almost any command on the end-user computer as they see fit, such as: reading emails, copying files, recording keystrokes, sending spam, making screenshots, etc.
Since the discovery of its findings, Finjan has provided US and UK law enforcement with information about the server. Finjan has also contacted affected corporate and government agencies to let them know that they were part of the infected computer names.
"As predicted by Finjan at the end of last year, cybercriminals keep on looking for improved methods to distribute their malware and Trojans are winning the race (http://www.finjan.com/Content.aspx?id=827#SecurityTrendsReport). The sophistication of the malware and the staggering amount of infected computers proves that cybergangs are raising the bar," said Yuval Ben-Itzhak, CTO of Finjan. "As big money drives today's cybercrime activities, organizations and corporations need to protect their valuable data to prevent theft by these kind of sophisticated cyberattacks."
The research also revealed that the malware is installed on computers when visiting compromised websites serving malicious code. Information found by MCRC on the command and control server includes the IP addresses of the infected computers as well as the computers' name inside corporate and government networks that are running the malware.
The global spread of infected computers in percentages is as follows:
- US: 45%
- UK: 6%
- Canada: 4%
- Germany: 4%
- France: 3%
- Other: 38%
The malware is infecting computers running the Windows XP operating
system and using the following Web browsers:
- Internet Explorer - 78%
- Firefox - 15%
- Opera - 3%
- Safari - 1%
- Other - 3%
As recommended by leading analysts, a unified Web security solution is the preferred solution for corporate and government agencies against today's cyber attacks. Finjan's Unified Secure Web Gateway (http://www.finjan.com/Content.aspx?id=190) product combines multi-layered Web security, utilizing real-time content inspection technologies, with data leakage prevention (DLP) solutions. Finjan's product also provides Web 2.0, productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies on one dedicated appliance. This enables companies and governmental agencies alike to enjoy optimal multi-layered protection in real-time, with lower Total Cost of Ownership (TCO) and higher Return on Investment (ROI).
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Labels:
atlanta,
botnet,
cyber crime,
fayette front page,
finjan,
georgia,
georgia front page,
malicious,
malware,
windows pc
Monday, January 19, 2009
New Rogue Websites Announcing Barack Obama's Resignation Turn Users' Computers into 'Zombies' says PandaLabs
/PRNewswire/ -- PandaLabs, Panda Security's malware analysis and detection laboratory, has detected 40 websites that are using Barack Obama, President-elect of the United States, as bait to spread malware. These pages contain the following headline: "Barack Obama has refused to be a President."
If users try to read the article a dialog box is displayed asking them to download a file. However, if they do so, a number of malicious files will infiltrate their computers. These files turn the affected computer into a 'zombie' computer, remotely controlled by cyber-criminals. An image of the fake Obama website can be viewed here: http://www.flickr.com/photos/panda_security/3209435502/.
"These zombie computers are normally networked to form 'botnets', as the malicious code that allows remotely controlling them is called a 'bot'," explains Ryan Sherstobitoff, chief corporate evangelist, Panda Security. "Botnets are then hired by cyber-crooks to third-parties that use zombie computers with malicious purposes such as sending spam or launching denial of service attacks."
According to PandaLabs, the attack appears have originated from China, as all domains have been bought to a Chinese company with a long record of malware attacks.
This is not the first time that Barack Obama has been used by cyber-criminals to distribute malware. Even during the presidential campaign and the days that followed the election, false news stories circulated that led to malware downloads.
For more information about this attack, go to the PandaLabs blog: http://pandalabs.pandasecurity.com/archive/Malware-Campaign-Impersonates-Barac k-Obama_2700_s-Website.aspx.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
If users try to read the article a dialog box is displayed asking them to download a file. However, if they do so, a number of malicious files will infiltrate their computers. These files turn the affected computer into a 'zombie' computer, remotely controlled by cyber-criminals. An image of the fake Obama website can be viewed here: http://www.flickr.com/photos/panda_security/3209435502/.
"These zombie computers are normally networked to form 'botnets', as the malicious code that allows remotely controlling them is called a 'bot'," explains Ryan Sherstobitoff, chief corporate evangelist, Panda Security. "Botnets are then hired by cyber-crooks to third-parties that use zombie computers with malicious purposes such as sending spam or launching denial of service attacks."
According to PandaLabs, the attack appears have originated from China, as all domains have been bought to a Chinese company with a long record of malware attacks.
This is not the first time that Barack Obama has been used by cyber-criminals to distribute malware. Even during the presidential campaign and the days that followed the election, false news stories circulated that led to malware downloads.
For more information about this attack, go to the PandaLabs blog: http://pandalabs.pandasecurity.com/archive/Malware-Campaign-Impersonates-Barac k-Obama_2700_s-Website.aspx.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Thursday, November 20, 2008
Major Spam Botnets Yet to Recover After Host Shut-Down
/PRNewswire/ -- One week after the world's most significant breakthrough in the fight against spam, spam levels are yet to return to their previous levels, according to security experts from the Marshal8e6 TRACE Team. However, it is likely that spam levels will eventually return to their previous high levels in the future.
On November 11, the volume of spam around the world fell by as much as 70 percent due to the shutdown of a major spam hosting network, McColo.
McColo was shut down by its Internet Service Provider after an investigative journalist made inquiries about the Web hosting company's illicit activities. McColo was hosting the command and control infrastructure for three of the world's most prolific spam botnets: Srizbi, Mega-D and Rustock. When McColo was shut down, the spammers were disconnected from the networks of spam-sending bot computers under their control.
Throughout 2008, the TRACE team has published reports showing that just a handful of major spamming botnets are responsible for as much as 90 percent of spam. The TRACE Team has been campaigning within the IT security community for a coordinated effort against the top spamming botnets.
"This is the most significant single event in the fight against spam we have ever seen," said Phil Hay, lead threat analyst with the TRACE Team. "It shows that a coordinated effort against spammers by security researchers can have a positive and meaningful impact on global spam levels. It is something that we have been working towards for a long time and it is fantastic to see the flow-on effects on spam levels as a result of targeting the bigger botnets."
"Unfortunately we do not expect this situation to last," he continued. "The spammers are no doubt already setting up new command and control servers. The challenge for them is to re-establish connections with the thousands of zombie computers still infected with their bot code. We fully expect spam will resume in large volumes eventually. However, almost a week later, the spammers haven't managed to do that yet."
Marshal8e6 says that the command and control servers play a critical part in managing the hundreds of thousands of infected bot computers, also referred to as 'zombies'.
"An infected bot computer typically 'phones home' to the control servers periodically to get updated instructions and spamming templates. By shutting down McColo, the link between the zombie computers and their control servers has effectively been cut off for now," explained Hay.
The events that led to McColo's shut down involved months of collaboration and research by a variety of security professionals.
"Last week's events have proven that by drawing attention to the worst spam offenders, security researchers and law enforcement have the capability to focus their energies on the key players and take action," said Hay. "Five years ago when spam was dominated by numerous small-scale spammers it was extremely difficult to target an individual spammer and have any real effect on spam. Now, because botnets have enabled a handful of major spam players to dominate, the targeted actions of the IT security and law enforcement communities can have an immediate and palpable effect on spam."
Marshal8e6 says the command and control servers for the Srizbi, Mega-D and Rustock botnets were affected by the McColo shut down. According to Marshal8e6's statistics, just prior to McColo's shut down, these three botnets were ranked first, second and fifth respectively as the world's most prolific sources of spam, together responsible for nearly 70 percent of spam.
"It is a cliche, but the fight against spam is a game of cat and mouse," said Hay. "Over the longer term, the spammers will learn from this incident and will probably evolve their botnet control systems. They may adopt a more resilient peer-to-peer or layered model where control servers are harder to access and spread among many hosts. Only time will tell if these botnets recover. The key thing is that the IT security and law enforcement communities learn from last week's events as well. We have to work together to maintain the pressure on the key spam players."
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
On November 11, the volume of spam around the world fell by as much as 70 percent due to the shutdown of a major spam hosting network, McColo.
McColo was shut down by its Internet Service Provider after an investigative journalist made inquiries about the Web hosting company's illicit activities. McColo was hosting the command and control infrastructure for three of the world's most prolific spam botnets: Srizbi, Mega-D and Rustock. When McColo was shut down, the spammers were disconnected from the networks of spam-sending bot computers under their control.
Throughout 2008, the TRACE team has published reports showing that just a handful of major spamming botnets are responsible for as much as 90 percent of spam. The TRACE Team has been campaigning within the IT security community for a coordinated effort against the top spamming botnets.
"This is the most significant single event in the fight against spam we have ever seen," said Phil Hay, lead threat analyst with the TRACE Team. "It shows that a coordinated effort against spammers by security researchers can have a positive and meaningful impact on global spam levels. It is something that we have been working towards for a long time and it is fantastic to see the flow-on effects on spam levels as a result of targeting the bigger botnets."
"Unfortunately we do not expect this situation to last," he continued. "The spammers are no doubt already setting up new command and control servers. The challenge for them is to re-establish connections with the thousands of zombie computers still infected with their bot code. We fully expect spam will resume in large volumes eventually. However, almost a week later, the spammers haven't managed to do that yet."
Marshal8e6 says that the command and control servers play a critical part in managing the hundreds of thousands of infected bot computers, also referred to as 'zombies'.
"An infected bot computer typically 'phones home' to the control servers periodically to get updated instructions and spamming templates. By shutting down McColo, the link between the zombie computers and their control servers has effectively been cut off for now," explained Hay.
The events that led to McColo's shut down involved months of collaboration and research by a variety of security professionals.
"Last week's events have proven that by drawing attention to the worst spam offenders, security researchers and law enforcement have the capability to focus their energies on the key players and take action," said Hay. "Five years ago when spam was dominated by numerous small-scale spammers it was extremely difficult to target an individual spammer and have any real effect on spam. Now, because botnets have enabled a handful of major spam players to dominate, the targeted actions of the IT security and law enforcement communities can have an immediate and palpable effect on spam."
Marshal8e6 says the command and control servers for the Srizbi, Mega-D and Rustock botnets were affected by the McColo shut down. According to Marshal8e6's statistics, just prior to McColo's shut down, these three botnets were ranked first, second and fifth respectively as the world's most prolific sources of spam, together responsible for nearly 70 percent of spam.
"It is a cliche, but the fight against spam is a game of cat and mouse," said Hay. "Over the longer term, the spammers will learn from this incident and will probably evolve their botnet control systems. They may adopt a more resilient peer-to-peer or layered model where control servers are harder to access and spread among many hosts. Only time will tell if these botnets recover. The key thing is that the IT security and law enforcement communities learn from last week's events as well. We have to work together to maintain the pressure on the key spam players."
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Labels:
atlanta,
botnet,
decrease,
fayette front page,
fayetteville,
georgia,
georgia front page,
illicit,
mccolo,
peachtree city,
security,
spam,
tyrone,
volume,
web host
Saturday, October 18, 2008
FBI: The Cyber Threat Today
Crooks and spies using the Internet to commit crimes against U.S. businesses and to attack government networks are getting more sophisticated, and the increasing number of such crimes not only impacts the economy but threatens national security.
That’s the message Shawn Henry, recently appointed head of the FBI Cyber Division, delivered to a group of reporters on Wednesday, revealing that we have thousands of open cases into cyber crimes and organized cyber attacks and detailing our strategy to protect the nation’s networks.
One case in point: We joined our international partners yesterday in announcing a major takedown of a transnational criminal network that was buying and selling stolen financial information through an online forum known as “Dark Market.”
“The business of the United States is done on the Internet,” said Henry, a veteran cyber crime investigator. And the information that flows electronically 24/7 is increasingly the target of not only identity thieves and scammers, but organized crime groups, terrorists, and overseas governments.
“There are a number of countries who have an interest in stealing information from the United States,” Henry said, explaining that as many as two dozen nations have taken an “aggressive interest” in penetrating our networks. In the past year, he added, “the malicious activity has become much more prevalent.”
Malicious activity could come in the form of attacks that deny access to websites, that compromise sensitive information, or that introduce “botnets” that spread viruses and covertly co-opt computers to carry out data theft.
“There are a number of countries who have an interest in stealing information from the United States,” Henry said, explaining that as many as two dozen nations have taken an “aggressive interest” in penetrating our networks.
New groups of hackers—virtual gangs—are a growing threat as well, banding together to pool their expertise and carry out coordinated cyber attacks. Henry pointed out that in years gone by, if a gang wanted to rob a bank, it needed crooks with various skills—safe cracker, get-away driver, look-out, etc. That’s essentially what we’re seeing in the cyber world today, only these virtual gang members have never met in the physical world. “There are organized groups that are very successful,” Henry said.
The 3 Ps. To address the rising threat, the Cyber Division has a threefold strategic plan—“Prioritize, Proactive, Partnerships.”
By prioritizing our efforts, we can go after the most critical threats. Being proactive means adopting the same time-tested investigative techniques that have been so successful in our physical crime investigations—the use of informants, electronic surveillance, and placement of undercover agents to penetrate and dismantle virtual criminal operations.
The third “P”—partnerships—means building even stronger relationships with law enforcement agencies worldwide. He said we’ve worked with such countries as Great Britain, Canada, Russia, and Turkey to swap best practices and techniques. We’ve also sent agents to Romania to work with law enforcement there, leading to nearly 100 arrests in cyber crime cases representing “tens of millions of dollars” in losses, Henry said.
And the Internet Crime Complaint Center, or IC3—a partnership between the FBI and the National White Collar Crime Center—continues to assist state and local law enforcement in fighting cyber crime. Since its establishment in 2000, IC3 has received more than a million complaints. In the last couple of years, there’s been an “uptick” in the number of reports, according to Henry. Lately, they’re coming in at the rate of nearly 20,000 per month.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
That’s the message Shawn Henry, recently appointed head of the FBI Cyber Division, delivered to a group of reporters on Wednesday, revealing that we have thousands of open cases into cyber crimes and organized cyber attacks and detailing our strategy to protect the nation’s networks.
One case in point: We joined our international partners yesterday in announcing a major takedown of a transnational criminal network that was buying and selling stolen financial information through an online forum known as “Dark Market.”
“The business of the United States is done on the Internet,” said Henry, a veteran cyber crime investigator. And the information that flows electronically 24/7 is increasingly the target of not only identity thieves and scammers, but organized crime groups, terrorists, and overseas governments.
“There are a number of countries who have an interest in stealing information from the United States,” Henry said, explaining that as many as two dozen nations have taken an “aggressive interest” in penetrating our networks. In the past year, he added, “the malicious activity has become much more prevalent.”
Malicious activity could come in the form of attacks that deny access to websites, that compromise sensitive information, or that introduce “botnets” that spread viruses and covertly co-opt computers to carry out data theft.
“There are a number of countries who have an interest in stealing information from the United States,” Henry said, explaining that as many as two dozen nations have taken an “aggressive interest” in penetrating our networks.
New groups of hackers—virtual gangs—are a growing threat as well, banding together to pool their expertise and carry out coordinated cyber attacks. Henry pointed out that in years gone by, if a gang wanted to rob a bank, it needed crooks with various skills—safe cracker, get-away driver, look-out, etc. That’s essentially what we’re seeing in the cyber world today, only these virtual gang members have never met in the physical world. “There are organized groups that are very successful,” Henry said.
The 3 Ps. To address the rising threat, the Cyber Division has a threefold strategic plan—“Prioritize, Proactive, Partnerships.”
By prioritizing our efforts, we can go after the most critical threats. Being proactive means adopting the same time-tested investigative techniques that have been so successful in our physical crime investigations—the use of informants, electronic surveillance, and placement of undercover agents to penetrate and dismantle virtual criminal operations.
The third “P”—partnerships—means building even stronger relationships with law enforcement agencies worldwide. He said we’ve worked with such countries as Great Britain, Canada, Russia, and Turkey to swap best practices and techniques. We’ve also sent agents to Romania to work with law enforcement there, leading to nearly 100 arrests in cyber crime cases representing “tens of millions of dollars” in losses, Henry said.
And the Internet Crime Complaint Center, or IC3—a partnership between the FBI and the National White Collar Crime Center—continues to assist state and local law enforcement in fighting cyber crime. Since its establishment in 2000, IC3 has received more than a million complaints. In the last couple of years, there’s been an “uptick” in the number of reports, according to Henry. Lately, they’re coming in at the rate of nearly 20,000 per month.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Thursday, October 16, 2008
Georgia Tech Information Security Center Releases Emerging Cyber Threats Forecast for 2009
(BUSINESS WIRE)--The Georgia Tech Information Security Center (GTISC), a national leader in information security research and education, today announced the release of the GTISC Emerging Cyber Threats Report for 2009, outlining the top five areas of security concern and risk for consumer and enterprise Internet users for the coming year. The report was released at the annual GTISC Security Summit on Emerging Cyber Security Threats – a gathering of leading industry and academic leaders from organizations with a stake in protecting the online user community.
For 2009, GTISC is forecasting five key cyber security areas where threats are expected to increase and evolve:
* Malware— specifically under the guise of benign social networking links
* Botnets – specifically the spread of botnet attacks to wireless and peer-to-peer networks
* Cyber warfare — including targets on the U.S. economy and infrastructure
* Threats to VoIP and Mobile Convergence—specifically voice fraud and cellular botnets
* The Evolving Cyber Crime Economy – including the rise of sophisticated malware-for-sale kits and programs
According to the report, data will continue to be the primary motive behind future cyber crime – whether targeting traditional fixed computing environments or mobile applications. Experts from across the IT security spectrum – from government to industry to academia – join GTISC’s call for closer coordination between the security industry, Internet Service Providers (ISPs), application developers and government regulators to safeguard the user community and hinder the spread of sophisticated cyber security threats.
“At GTISC, we strongly believe that a proactive approach to understanding emerging threats will help us develop more effective information security technologies and strategies,” said Mustaque Ahamad, director of GTISC. “The annual GTISC Security Summit on Emerging Cyber Security Threats and this report seek to give us a better understanding of the increasingly sophisticated cyber security challenges we will face in the years ahead. We wish to thank the esteemed members of the IT security community who assisted us with the creation of this report.”
More than 300 corporate executives, industry leaders and technologists from across the country attended the GTISC Security Summit on Emerging Cyber Security Threats, keynoted by Lt. General Robert J. Elder, Jr., Commander Eighth Air Force of the Barksdale Air Force Base. Following Lt. Elder’s address on “Global Operations and Mission Assurance in a Contested Cyber Environment” in the morning, Summit panelists engaged in a lively discussion moderated by IT Security Entrepreneur, Thomas E. Noonan. This year’s panelists, from the U.S. Department of Homeland Security, IBM Internet Security Systems, the Georgia Institute of Technology, Cisco, Motorola and SecureWorks, helped to educate the audience on the proliferation of cyber threats, including those listed in the report, and highlighted possible countermeasures to safeguard the user and business communities.
To view the entire GTISC Emerging Cyber Threats for 2009 report or to watch a pre-recorded Web cast of the Summit, please visit http://www.gtiscsecuritysummit.com.
-----
www.georgiafrontpage.com
Georgia Front Page
www.fayettefrontpage.com
Fayette Front Page
News to Use in Fayetteville, Atlanta, Savannah, Peachtree City and all of Georgia
For 2009, GTISC is forecasting five key cyber security areas where threats are expected to increase and evolve:
* Malware— specifically under the guise of benign social networking links
* Botnets – specifically the spread of botnet attacks to wireless and peer-to-peer networks
* Cyber warfare — including targets on the U.S. economy and infrastructure
* Threats to VoIP and Mobile Convergence—specifically voice fraud and cellular botnets
* The Evolving Cyber Crime Economy – including the rise of sophisticated malware-for-sale kits and programs
According to the report, data will continue to be the primary motive behind future cyber crime – whether targeting traditional fixed computing environments or mobile applications. Experts from across the IT security spectrum – from government to industry to academia – join GTISC’s call for closer coordination between the security industry, Internet Service Providers (ISPs), application developers and government regulators to safeguard the user community and hinder the spread of sophisticated cyber security threats.
“At GTISC, we strongly believe that a proactive approach to understanding emerging threats will help us develop more effective information security technologies and strategies,” said Mustaque Ahamad, director of GTISC. “The annual GTISC Security Summit on Emerging Cyber Security Threats and this report seek to give us a better understanding of the increasingly sophisticated cyber security challenges we will face in the years ahead. We wish to thank the esteemed members of the IT security community who assisted us with the creation of this report.”
More than 300 corporate executives, industry leaders and technologists from across the country attended the GTISC Security Summit on Emerging Cyber Security Threats, keynoted by Lt. General Robert J. Elder, Jr., Commander Eighth Air Force of the Barksdale Air Force Base. Following Lt. Elder’s address on “Global Operations and Mission Assurance in a Contested Cyber Environment” in the morning, Summit panelists engaged in a lively discussion moderated by IT Security Entrepreneur, Thomas E. Noonan. This year’s panelists, from the U.S. Department of Homeland Security, IBM Internet Security Systems, the Georgia Institute of Technology, Cisco, Motorola and SecureWorks, helped to educate the audience on the proliferation of cyber threats, including those listed in the report, and highlighted possible countermeasures to safeguard the user and business communities.
To view the entire GTISC Emerging Cyber Threats for 2009 report or to watch a pre-recorded Web cast of the Summit, please visit http://www.gtiscsecuritysummit.com.
-----
www.georgiafrontpage.com
Georgia Front Page
www.fayettefrontpage.com
Fayette Front Page
News to Use in Fayetteville, Atlanta, Savannah, Peachtree City and all of Georgia
Labels:
atlanta,
botnet,
cyber threat,
fayette front page,
fayetteville,
georgia,
georgia front page,
georgia tech,
internet,
malware,
peachtree city,
safety,
security,
summit,
threat,
tyrone,
warfare
Subscribe to:
Posts (Atom)