Click here to close now.


Wearables Authors: Yeshim Deniz, SmartBear Blog, Elizabeth White, Tim Fujita-Yuhas, Pat Romanski

News Feed Item

Radware Releases Global Security Report - Reveals New Cyber Attack Methods Uncovering Blind-Spots Unrecognized by Security Professionals and Organizations

Server-based botnets and HTTPS layer attacks among the tactics leveraged by hackers in some of 2012's most notorious attacks

MAHWAH, New Jersey, January 22, 2013 /PRNewswire/ --

In the face of an ever-evolving cyber security landscape, researchers at Radware® (NASDAQ: RDWR), a leading provider of application delivery and application security solutions for virtual and cloud data centers, have identified a number of new attack methods representative of today's increasingly sophisticated and severe distributed-denial-of-service (DDoS) threat. Radware's 2012 Global Application and Network Security Report highlights server-based botnets and encrypted layer attacks as just two of the new attack tools challenging organizations during DDoS attacks. Most recently, these tactics were leveraged by perpetrators in the attacks against U.S. financial institutions that have been ongoing since September 2012.

Prepared by Radware's Emergency Response Team (ERT) which actively monitors and mitigates attacks in real-time, the in-depth research report also found that while security organizations have focused their efforts and attention on the pre and post-phases of defense, attackers now launch prolonged attacks that last days or weeks. This has created a vulnerable blind-spot as defenders lack the capabilities and resources to mitigate attacks in the "during" phase which attackers can exploit to their advantage.  

"The Radware ERT sees hundreds of DoS/DDoS attacks each year, and we've found attacks lasting more than one week have doubled in frequency during 2012," says Avi Chesla, chief technology officer at Radware. Through empirical and statistical research coupled with front-line experience, our team identified trends that can help educate the security community.

"Through highlighting significant trends found in this report, our goal is to provide actionable intelligence to ensure organizations can better detect and mitigate these threats that plague their network infrastructure," adds Chesla.

Key findings from the report include:

  • Server-based botnets represent a new and more powerful order in the DDoS environment. The shift from single-server attacks to the use of multiple servers in different geographic locations has allowed attackers to quickly and effectively launch more powerful DDoS attacks than ever before. Just a few attacking servers can produce the same attack traffic as a large number of client botnets, with the 24/7 availability of servers allowing for greater reliability as well as command-and-control. In 2013, Radware expects this method to gain in popularity, requiring that organizations make sure their defense architecture can withstand these scaled up attacks. Although effective, several weak points are uncovered and identified. 
  • The number of DDoS and DoS attacks lasting more than one week doubled  in 2012. Radware's ERT developed the Advanced Persistent Threat (APT) score to quantify and qualify the increasing force, sophistical and persistence of 2012's attacks. The numbers are staggering - with 58 percent of attacks scoring a 7 or higher in complexity (out of 10), as compared to just 23 percent of attacks in 2011. In 2011, only 30% of attacks scored higher than a level of 3 in terms of severity, while in 2012 70% achieved a level of 3 or higher.
  • Encrypted layer attacks fly below the radar - and can't be ignored. In 2012, the growing popularity of HTTPS-based attacks added a new dimension to the security landscape. Though conventionally associated with security on the web, hackers have managed to weaponize the encryption layer, using it to launch application-level and SSL attacks that can escape detection and remain hidden until its already too late. This has become an especially troubling phenomenon for financial services and e-commerce websites that rely heavily on HTTPS.
  • In today's security environment, most organizations are bringing a knife to a gunfight. With some of the worlds largest institutions victimized by cyber attacks in 2012, the question remains as to why many of these organizations continue to be vulnerable. The fact remains that less than a quarter of all organizations surveyed invest their efforts in mitigating attacks as they're happening - a fact exploited by hackers. In 2013, Radware recommends that organizations dedicate resources to creating a "security war room" equipped to dynamically respond to and handle persistent security attacks during all phases of an attack and adopt a three-phased security approach.
  • The 'DIY' phenomenon.  The proliferation of 'do-it-yourself' sites devoted to enabling hacking schemes has reached commodity market proportions. The supply chain includes took kits and for-hire services that are available to anyone with minimal coding or advanced hacking skills for as little as $10 for a ransomware attack tool.  This has significantly reduced the barrier of entry for individuals or organizations to launch an attack.  

The report which doubles as a resource guide that security professionals can easily reference also features recommendations that organizations can adopt to safeguard themselves against emerging attack trends and techniques. Chief among these recommendations are:

  • How to Stop Sophisticated Attack Campaigns.  Organizations usually administer a two-phase "pre and post" attack security approach as their defense strategy. Sophisticated campaigns can only be eradicated by setting a third-phase security approach during the attack. A cadre of external "on-demand" force multiplier teams who can dynamically respond and employ tactics to mitigate future attacks needs to be implemented by an organization. A typical, persistent DDoS attack requires no less than 9 security engineers  for sufficient defense.    
  • Examination Lines of Defense. Mitigation may have improved, but this has also pushed attackers to invest in finding the weak links in lines of defense. Organizations should ensure that their line of defense is comprehensive. As part of this, a mitigation checklist must be completed, with any missing elements in to be addressed.
  • Carefully Consider Network Architecture. To be effective, a DoS / DDoS mitigation solution must be placed before most of the network elements in the path, which is not the traditional deployment. Additionally, if a content delivery network (CDN) is the primary DDoS mitigation solution, ensure you complement it with a customer premise equipment (CPE) solution for optimal protection.

To download the complete 2012 Global Network & Application Security Report, which includes the ERT's recommendations for how organizations can best prepare for mitigating cyber threats in 2013, please visit

Additional Resources

ERT Video: Matthew Andriani, ERT Specialist discusses APT Scoring (

ERT Video: Ziv Gadot, ERT Team Leader discusses how to stop sophisticated attack campaigns (

Slideshare Presentation:


About the Radware Emergency Response Team (ERT)

Radware's ERT is a group of dedicated security consultants who are available around the clock.  As literal "first responders" to cyber attacks, Radware's ERT members gained their extensive experience by successfully dealing with some of the industry's most notable hacking episodes, providing the knowledge and expertise to mitigate the kind of attack a business's security team may never have handled.  Through the report, the ERT reveals how their in-the-trenches experiences fighting cyber attacks provide deeper forensic analysis than surveys alone or academic research.

About the 2012 Global Network & Application Security Report

Radware's annual Global Application & Network Security Report provides insight into network security trends with a specific focus on DoS/DDoS attacks.  Intended for the entire security community, this research is designed to deliver a comprehensive and objective summary of network security events and DoS / DDoS attacks that took place in 2012, with an analysis of attack types, trends and mitigation technologies.  Altogether, the report draws its information from 274 organizations from two sources: Radware's Industry Security Review and key security cases from Radware's Emergency Response Team.

About Radware

Radware (NASDAQ: RDWR), is a global leader of application delivery and application security solutions for virtual and cloud data centers. Its award-winning solutions portfolio delivers full resilience for business-critical applications, maximum IT efficiency, and complete business agility.

Radware's solutions empower more than 10,000 enterprise and carrier customers worldwide to adapt to market challenges quickly, maintain business continuity and achieve maximum productivity while keeping costs down.  For more information, please visit

Radware encourages you to join our community and follow us on; LinkedIn, Radware Blog, Twitter, YouTube, Radware Connect app for iPhone® and our new security center that provides a comprehensive analysis on DDoS attack tools, trends and threats.

©2013 Radware, Ltd. All rights reserved. Radware and all other Radware product and service names are registered trademarks or trademarks of Radware in the U.S. and other countries. All other trademarks and names are property of their respective owners.

This press release may contain statements concerning Radware's future prospects that are "forward-looking statements" under the Private Securities Litigation Reform Act of 1995. Statements preceded by, followed by, or that otherwise include the words "believes", "expects", "anticipates", "intends", "estimates", "plans", and similar expressions or future or conditional verbs such as "will", "should", "would", "may" and "could" are generally forward-looking in nature and not historical facts. These statements are based on current expectations and projections that involve a number of risks and uncertainties.  There can be no assurance that future results will be achieved, and actual results could differ materially from forecasts and estimates.  These risks and uncertainties, as well as others, are discussed in greater detail in Radware's Annual Report on Form 20-F and Radware's other filings with the Securities and Exchange Commission.  Forward-looking statements speak only as of the date on which they are made and Radware undertakes no commitment to revise or update any forward-looking statement in order to reflect events or circumstances after the date any such statement is made.  Radware's public filings are available from the Securities and Exchange Commission's website at  or may be obtained on Radware's website at

Corporate Media Relations:

Brian T. Gallagher
+1-201-785-3206  (office)
+1-201-574-3840  (cell)
[email protected]

SOURCE Radware Ltd

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
WebRTC is about the data channel as much as about video and audio conferencing. However, basically all commercial WebRTC applications have been built with a focus on audio and video. The handling of “data” has been limited to text chat and file download – all other data sharing seems to end with screensharing. What is holding back a more intensive use of peer-to-peer data? In her session at @ThingsExpo, Dr Silvia Pfeiffer, WebRTC Applications Team Lead at National ICT Australia, will look at different existing uses of peer-to-peer data sharing and how it can become useful in a live session to...
NHK, Japan Broadcasting, will feature the upcoming @ThingsExpo Silicon Valley in a special 'Internet of Things' and smart technology documentary that will be filmed on the expo floor between November 3 to 5, 2015, in Santa Clara. NHK is the sole public TV network in Japan equivalent to the BBC in the UK and the largest in Asia with many award-winning science and technology programs. Japanese TV is producing a documentary about IoT and Smart technology and will be covering @ThingsExpo Silicon Valley. The program, to be aired during the peak viewership season of the year, will have a major impac...
The buzz continues for cloud, data analytics and the Internet of Things (IoT) and their collective impact across all industries. But a new conversation is emerging - how do companies use industry disruption and technology enablers to lead in markets undergoing change, uncertainty and ambiguity? Organizations of all sizes need to evolve and transform, often under massive pressure, as industry lines blur and merge and traditional business models are assaulted and turned upside down. In this new data-driven world, marketplaces reign supreme while interoperability, APIs and applications deliver un...
Developing software for the Internet of Things (IoT) comes with its own set of challenges. Security, privacy, and unified standards are a few key issues. In addition, each IoT product is comprised of at least three separate application components: the software embedded in the device, the backend big-data service, and the mobile application for the end user's controls. Each component is developed by a different team, using different technologies and practices, and deployed to a different stack/target - this makes the integration of these separate pipelines and the coordination of software upd...
Internet of Things (IoT) will be a hybrid ecosystem of diverse devices and sensors collaborating with operational and enterprise systems to create the next big application. In their session at @ThingsExpo, Bramh Gupta, founder and CEO of, and Fred Yatzeck, principal architect leading product development at, discussed how choosing the right middleware and integration strategy from the get-go will enable IoT solution developers to adapt and grow with the industry, while at the same time reduce Time to Market (TTM) by using plug and play capabilities offered by a robust IoT ...
Through WebRTC, audio and video communications are being embedded more easily than ever into applications, helping carriers, enterprises and independent software vendors deliver greater functionality to their end users. With today’s business world increasingly focused on outcomes, users’ growing calls for ease of use, and businesses craving smarter, tighter integration, what’s the next step in delivering a richer, more immersive experience? That richer, more fully integrated experience comes about through a Communications Platform as a Service which allows for messaging, screen sharing, video...
Can call centers hang up the phones for good? Intuitive Solutions did. WebRTC enabled this contact center provider to eliminate antiquated telephony and desktop phone infrastructure with a pure web-based solution, allowing them to expand beyond brick-and-mortar confines to a home-based agent model. It also ensured scalability and better service for customers, including MUY! Companies, one of the country's largest franchise restaurant companies with 232 Pizza Hut locations. This is one example of WebRTC adoption today, but the potential is limitless when powered by IoT.
SYS-CON Events announced today that Luxoft Holding, Inc., a leading provider of software development services and innovative IT solutions, has been named “Bronze Sponsor” of SYS-CON's @ThingsExpo, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Luxoft’s software development services consist of core and mission-critical custom software development and support, product engineering and testing, and technology consulting.
“In the past year we've seen a lot of stabilization of WebRTC. You can now use it in production with a far greater degree of certainty. A lot of the real developments in the past year have been in things like the data channel, which will enable a whole new type of application," explained Peter Dunkley, Technical Director at Acision, in this interview at @ThingsExpo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
"Matrix is an ambitious open standard and implementation that's set up to break down the fragmentation problems that exist in IP messaging and VoIP communication," explained John Woolf, Technical Evangelist at Matrix, in this interview at @ThingsExpo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
You have your devices and your data, but what about the rest of your Internet of Things story? Two popular classes of technologies that nicely handle the Big Data analytics for Internet of Things are Apache Hadoop and NoSQL. Hadoop is designed for parallelizing analytical work across many servers and is ideal for the massive data volumes you create with IoT devices. NoSQL databases such as Apache HBase are ideal for storing and retrieving IoT data as “time series data.”
There are so many tools and techniques for data analytics that even for a data scientist the choices, possible systems, and even the types of data can be daunting. In his session at @ThingsExpo, Chris Harrold, Global CTO for Big Data Solutions for EMC Corporation, will show how to perform a simple, but meaningful analysis of social sentiment data using freely available tools that take only minutes to download and install. Participants will get the download information, scripts, and complete end-to-end walkthrough of the analysis from start to finish. Participants will also be given the pract...
Clearly the way forward is to move to cloud be it bare metal, VMs or containers. One aspect of the current public clouds that is slowing this cloud migration is cloud lock-in. Every cloud vendor is trying to make it very difficult to move out once a customer has chosen their cloud. In his session at 17th Cloud Expo, Naveen Nimmu, CEO of Clouber, Inc., will advocate that making the inter-cloud migration as simple as changing airlines would help the entire industry to quickly adopt the cloud without worrying about any lock-in fears. In fact by having standard APIs for IaaS would help PaaS expl...
SYS-CON Events announced today that ProfitBricks, the provider of painless cloud infrastructure, will exhibit at SYS-CON's 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. ProfitBricks is the IaaS provider that offers a painless cloud experience for all IT users, with no learning curve. ProfitBricks boasts flexible cloud servers and networking, an integrated Data Center Designer tool for visual control over the cloud and the best price/performance value available. ProfitBricks was named one of the coolest Clo...
Organizations already struggle with the simple collection of data resulting from the proliferation of IoT, lacking the right infrastructure to manage it. They can't only rely on the cloud to collect and utilize this data because many applications still require dedicated infrastructure for security, redundancy, performance, etc. In his session at 17th Cloud Expo, Emil Sayegh, CEO of Codero Hosting, will discuss how in order to resolve the inherent issues, companies need to combine dedicated and cloud solutions through hybrid hosting – a sustainable solution for the data required to manage I...
Mobile messaging has been a popular communication channel for more than 20 years. Finnish engineer Matti Makkonen invented the idea for SMS (Short Message Service) in 1984, making his vision a reality on December 3, 1992 by sending the first message ("Happy Christmas") from a PC to a cell phone. Since then, the technology has evolved immensely, from both a technology standpoint, and in our everyday uses for it. Originally used for person-to-person (P2P) communication, i.e., Sally sends a text message to Betty – mobile messaging now offers tremendous value to businesses for customer and empl...
Scott Guthrie's keynote presentation "Journey to the intelligent cloud" is a must view video. This is from AzureCon 2015, September 29, 2015 I have reproduced some screen shots in case you are unable to view this long video for one reason or another. One of the highlights is 3 datacenters coming on line in India.
Nowadays, a large number of sensors and devices are connected to the network. Leading-edge IoT technologies integrate various types of sensor data to create a new value for several business decision scenarios. The transparent cloud is a model of a new IoT emergence service platform. Many service providers store and access various types of sensor data in order to create and find out new business values by integrating such data.
SYS-CON Events announced today that IBM Cloud Data Services has been named “Bronze Sponsor” of SYS-CON's 17th Cloud Expo, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. IBM Cloud Data Services offers a portfolio of integrated, best-of-breed cloud data services for developers focused on mobile computing and analytics use cases.
Apps and devices shouldn't stop working when there's limited or no network connectivity. Learn how to bring data stored in a cloud database to the edge of the network (and back again) whenever an Internet connection is available. In his session at 17th Cloud Expo, Bradley Holt, Developer Advocate at IBM Cloud Data Services, will demonstrate techniques for replicating cloud databases with devices in order to build offline-first mobile or Internet of Things (IoT) apps that can provide a better, faster user experience, both offline and online. The focus of this talk will be on IBM Cloudant, Apa...