- Recommend:
- 0 Comments
FBI, Industry Scramble to Stop Hack Attacks
Web sites assess their vulnerabilities in the face of cybervandalism.
"We are committed in every way possible to tracking down those who are responsible, to bringing them to justice, and to seeing that the law is enforced," Attorney General Janet Reno told a news conference at FBI headquarters Wednesday.
As the Feds scrambled to find the culprits, Webmasters across the Internet were checking for security holes that would permit attacks and rogue software that lets hackers use their sites as launch pads.
"Out of this will come new measures to strengthen things in the future," says Bill Wilson, president of Arca Systems, a security company that is a subsidiary of major Web-hosting company Exodus.
The attacks started Monday when Yahoo's servers were overloaded by false requests. Attacks followed on eBay, Buy.com, CNN.com, and Amazon. Next to be hit were ZDNet and E-Trade, both attacked early Wednesday.
However, the hacker offensive was set in motion much earlier, with software planted in computers throughout the network, says Sami Ahvenniemi, director of SSH Communications Security. "Hackers got into places like university networks or ISPs and seeded software on those computers. Now they've activated this software."
The intruders might have eavesdropped on passwords or log-ons, Ahvenniemi says. "That can be prevented by encryption."
But Bruce Schneier, president of the Internet securities firm Counterpane Systems, says encryption won't help because of the chain reaction of this kind of attack.
"Basically, the model of the attack is that someone would break into 1000 small sites, install an attack script, and then coordinate attacks against targets," Schneier says. "You might know where's it's coming from but not who."
What's a Site to Do?
Security companies recommend filters and other technology to block certain kinds of access. Unfortunately, that contradicts the very open nature of the Web.
Denials of service aren't new; they've been attempted on a smaller scale. This time, the size and high profile of companies makes them notable, says Wilson of Arca Systems. "The important thing is how companies respond to attacks."
"One can take steps such as hardening the servers," Wilson says. That means checking regularly for obvious weaknesses. It also helps to secure your systems from being used to launch such attacks, he adds.
The recent attacks hit so many servers that people haven't been able to filter them quickly enough, Ahvenniemi says.
Preparedness is key, according to Schneier. "The only thing to do is recognize that the products are inherently flawed, so you need to build processes to deal with them. Yahoo taking three hours to go up again means they weren't prepared."
An Internet company must periodically assess its servers, Wilson says. As companies grow rapidly, they must be careful not to "introduce vulnerabilities when expanding."
The victims of the past week's attacks took reasonable steps to deal with the moment, Wilson says. The whole Web community is learning from the experience.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Hack Attacks Proliferate with CIA, State of Alabama Latest Victims
- Comodo CEO Says DigiNotar Hack Was State-Sponsored
- Cybercrime Fight Costing Companies More This Year
- LulzSec, Anonymous Hacks Were Avoidable, Report Says
- New Sony Hack Nabs User Data of 2000 Customers
- Confidential Client List Safe from Anonymous, Says Hacker Target
- U.S. Government Says Cyber Attacks May Be Acts of War
- Pavilion 2711x Black 27" Widescreen LCD Monitor See All Prices
- VA2431wm Black 24" Widescreen LCD Monitor See All Prices
- 2770VH-1 27" LCD Monitor See All Prices
- Acer T231H 23 LCD Touchscreen Monitor - 1920 x 1080 - 16:9 - 2 ms - Adjustable Display Angle - 16.7 Million Colors - 80000:1 - 300 Nit - Speakers - DVI - HDMI - VGA - Black - Energy Star See All Prices
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.
















