Welcome!

Wearables Authors: XebiaLabs Blog, Liz McMillan, Elizabeth White, PagerDuty Blog, Carmen Gonzalez

News Feed Item

Radware Releases Global Security Report - Reveals New Cyber Attack Methods Uncovering Blind-Spots Unrecognized by Security Professionals and Organizations

Server-based botnets and HTTPS layer attacks among the tactics leveraged by hackers in some of 2012's most notorious attacks

MAHWAH, New Jersey, January 22, 2013 /PRNewswire/ --

In the face of an ever-evolving cyber security landscape, researchers at Radware® (NASDAQ: RDWR), a leading provider of application delivery and application security solutions for virtual and cloud data centers, have identified a number of new attack methods representative of today's increasingly sophisticated and severe distributed-denial-of-service (DDoS) threat. Radware's 2012 Global Application and Network Security Report highlights server-based botnets and encrypted layer attacks as just two of the new attack tools challenging organizations during DDoS attacks. Most recently, these tactics were leveraged by perpetrators in the attacks against U.S. financial institutions that have been ongoing since September 2012.

Prepared by Radware's Emergency Response Team (ERT) which actively monitors and mitigates attacks in real-time, the in-depth research report also found that while security organizations have focused their efforts and attention on the pre and post-phases of defense, attackers now launch prolonged attacks that last days or weeks. This has created a vulnerable blind-spot as defenders lack the capabilities and resources to mitigate attacks in the "during" phase which attackers can exploit to their advantage.  

"The Radware ERT sees hundreds of DoS/DDoS attacks each year, and we've found attacks lasting more than one week have doubled in frequency during 2012," says Avi Chesla, chief technology officer at Radware. Through empirical and statistical research coupled with front-line experience, our team identified trends that can help educate the security community.

"Through highlighting significant trends found in this report, our goal is to provide actionable intelligence to ensure organizations can better detect and mitigate these threats that plague their network infrastructure," adds Chesla.

Key findings from the report include:

  • Server-based botnets represent a new and more powerful order in the DDoS environment. The shift from single-server attacks to the use of multiple servers in different geographic locations has allowed attackers to quickly and effectively launch more powerful DDoS attacks than ever before. Just a few attacking servers can produce the same attack traffic as a large number of client botnets, with the 24/7 availability of servers allowing for greater reliability as well as command-and-control. In 2013, Radware expects this method to gain in popularity, requiring that organizations make sure their defense architecture can withstand these scaled up attacks. Although effective, several weak points are uncovered and identified. 
  • The number of DDoS and DoS attacks lasting more than one week doubled  in 2012. Radware's ERT developed the Advanced Persistent Threat (APT) score to quantify and qualify the increasing force, sophistical and persistence of 2012's attacks. The numbers are staggering - with 58 percent of attacks scoring a 7 or higher in complexity (out of 10), as compared to just 23 percent of attacks in 2011. In 2011, only 30% of attacks scored higher than a level of 3 in terms of severity, while in 2012 70% achieved a level of 3 or higher.
  • Encrypted layer attacks fly below the radar - and can't be ignored. In 2012, the growing popularity of HTTPS-based attacks added a new dimension to the security landscape. Though conventionally associated with security on the web, hackers have managed to weaponize the encryption layer, using it to launch application-level and SSL attacks that can escape detection and remain hidden until its already too late. This has become an especially troubling phenomenon for financial services and e-commerce websites that rely heavily on HTTPS.
  • In today's security environment, most organizations are bringing a knife to a gunfight. With some of the worlds largest institutions victimized by cyber attacks in 2012, the question remains as to why many of these organizations continue to be vulnerable. The fact remains that less than a quarter of all organizations surveyed invest their efforts in mitigating attacks as they're happening - a fact exploited by hackers. In 2013, Radware recommends that organizations dedicate resources to creating a "security war room" equipped to dynamically respond to and handle persistent security attacks during all phases of an attack and adopt a three-phased security approach.
  • The 'DIY' phenomenon.  The proliferation of 'do-it-yourself' sites devoted to enabling hacking schemes has reached commodity market proportions. The supply chain includes took kits and for-hire services that are available to anyone with minimal coding or advanced hacking skills for as little as $10 for a ransomware attack tool.  This has significantly reduced the barrier of entry for individuals or organizations to launch an attack.  

The report which doubles as a resource guide that security professionals can easily reference also features recommendations that organizations can adopt to safeguard themselves against emerging attack trends and techniques. Chief among these recommendations are:

  • How to Stop Sophisticated Attack Campaigns.  Organizations usually administer a two-phase "pre and post" attack security approach as their defense strategy. Sophisticated campaigns can only be eradicated by setting a third-phase security approach during the attack. A cadre of external "on-demand" force multiplier teams who can dynamically respond and employ tactics to mitigate future attacks needs to be implemented by an organization. A typical, persistent DDoS attack requires no less than 9 security engineers  for sufficient defense.    
  • Examination Lines of Defense. Mitigation may have improved, but this has also pushed attackers to invest in finding the weak links in lines of defense. Organizations should ensure that their line of defense is comprehensive. As part of this, a mitigation checklist must be completed, with any missing elements in to be addressed.
  • Carefully Consider Network Architecture. To be effective, a DoS / DDoS mitigation solution must be placed before most of the network elements in the path, which is not the traditional deployment. Additionally, if a content delivery network (CDN) is the primary DDoS mitigation solution, ensure you complement it with a customer premise equipment (CPE) solution for optimal protection.

To download the complete 2012 Global Network & Application Security Report, which includes the ERT's recommendations for how organizations can best prepare for mitigating cyber threats in 2013, please visit http://www.radware.com/globalsecurityreport

Additional Resources

ERT Video: Matthew Andriani, ERT Specialist discusses APT Scoring (http://youtu.be/L8tfWlPbRzg)

ERT Video: Ziv Gadot, ERT Team Leader discusses how to stop sophisticated attack campaigns (http://youtu.be/y0i5yQ_rJUY)

Slideshare Presentation: http://www.slideshare.net/Radware/2012-global-application-and

Blog: http://blog.radware.com/security/

About the Radware Emergency Response Team (ERT)

Radware's ERT is a group of dedicated security consultants who are available around the clock.  As literal "first responders" to cyber attacks, Radware's ERT members gained their extensive experience by successfully dealing with some of the industry's most notable hacking episodes, providing the knowledge and expertise to mitigate the kind of attack a business's security team may never have handled.  Through the report, the ERT reveals how their in-the-trenches experiences fighting cyber attacks provide deeper forensic analysis than surveys alone or academic research.

About the 2012 Global Network & Application Security Report

Radware's annual Global Application & Network Security Report provides insight into network security trends with a specific focus on DoS/DDoS attacks.  Intended for the entire security community, this research is designed to deliver a comprehensive and objective summary of network security events and DoS / DDoS attacks that took place in 2012, with an analysis of attack types, trends and mitigation technologies.  Altogether, the report draws its information from 274 organizations from two sources: Radware's Industry Security Review and key security cases from Radware's Emergency Response Team.

About Radware

Radware (NASDAQ: RDWR), is a global leader of application delivery and application security solutions for virtual and cloud data centers. Its award-winning solutions portfolio delivers full resilience for business-critical applications, maximum IT efficiency, and complete business agility.

Radware's solutions empower more than 10,000 enterprise and carrier customers worldwide to adapt to market challenges quickly, maintain business continuity and achieve maximum productivity while keeping costs down.  For more information, please visit http://www.radware.com.

Radware encourages you to join our community and follow us on; LinkedIn, Radware Blog, Twitter, YouTube, Radware Connect app for iPhone® and our new security center DDoSWarriors.com that provides a comprehensive analysis on DDoS attack tools, trends and threats.

©2013 Radware, Ltd. All rights reserved. Radware and all other Radware product and service names are registered trademarks or trademarks of Radware in the U.S. and other countries. All other trademarks and names are property of their respective owners.

This press release may contain statements concerning Radware's future prospects that are "forward-looking statements" under the Private Securities Litigation Reform Act of 1995. Statements preceded by, followed by, or that otherwise include the words "believes", "expects", "anticipates", "intends", "estimates", "plans", and similar expressions or future or conditional verbs such as "will", "should", "would", "may" and "could" are generally forward-looking in nature and not historical facts. These statements are based on current expectations and projections that involve a number of risks and uncertainties.  There can be no assurance that future results will be achieved, and actual results could differ materially from forecasts and estimates.  These risks and uncertainties, as well as others, are discussed in greater detail in Radware's Annual Report on Form 20-F and Radware's other filings with the Securities and Exchange Commission.  Forward-looking statements speak only as of the date on which they are made and Radware undertakes no commitment to revise or update any forward-looking statement in order to reflect events or circumstances after the date any such statement is made.  Radware's public filings are available from the Securities and Exchange Commission's website at http://www.sec.gov  or may be obtained on Radware's website at http://www.radware.com.

Corporate Media Relations:

Brian T. Gallagher
+1-201-785-3206  (office)
+1-201-574-3840  (cell)
[email protected]

SOURCE Radware Ltd

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
SYS-CON Events announced today that T-Mobile will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. As America's Un-carrier, T-Mobile US, Inc., is redefining the way consumers and businesses buy wireless services through leading product and service innovation. The Company's advanced nationwide 4G LTE network delivers outstanding wireless experiences to 67.4 million customers who are unwilling to compromise on ...
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
SYS-CON Events announced today that CollabNet, a global leader in enterprise software development, release automation and DevOps solutions, will be a Bronze Sponsor of SYS-CON's 20th International Cloud Expo®, taking place from June 6-8, 2017, at the Javits Center in New York City, NY. CollabNet offers a broad range of solutions with the mission of helping modern organizations deliver quality software at speed. The company’s latest innovation, the DevOps Lifecycle Manager (DLM), supports Value S...
Cybersecurity is a critical component of software development in many industries including medical devices. However, code is not always written to be robust or secure from the unknown or the unexpected. This gap can make medical devices susceptible to cybersecurity attacks ranging from compromised personal health information to life-sustaining treatment. In his session at @ThingsExpo, Clark Fortney, Software Engineer at Battelle, will discuss how programming oversight using key methods can incre...
SYS-CON Events announced today that Hitachi, the leading provider the Internet of Things and Digital Transformation, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Hitachi Data Systems, a wholly owned subsidiary of Hitachi, Ltd., offers an integrated portfolio of services and solutions that enable digital transformation through enhanced data management, governance, mobility and analytics. We help globa...
SYS-CON Events announced today that Juniper Networks (NYSE: JNPR), an industry leader in automated, scalable and secure networks, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Juniper Networks challenges the status quo with products, solutions and services that transform the economics of networking. The company co-innovates with customers and partners to deliver automated, scalable and secure network...
NHK, Japan Broadcasting, will feature the upcoming @ThingsExpo Silicon Valley in a special 'Internet of Things' and smart technology documentary that will be filmed on the expo floor between November 3 to 5, 2015, in Santa Clara. NHK is the sole public TV network in Japan equivalent to the BBC in the UK and the largest in Asia with many award-winning science and technology programs. Japanese TV is producing a documentary about IoT and Smart technology and will be covering @ThingsExpo Silicon Val...
New competitors, disruptive technologies, and growing expectations are pushing every business to both adopt and deliver new digital services. This ‘Digital Transformation’ demands rapid delivery and continuous iteration of new competitive services via multiple channels, which in turn demands new service delivery techniques – including DevOps. In this power panel at @DevOpsSummit 20th Cloud Expo, moderated by DevOps Conference Co-Chair Andi Mann, panelists will examine how DevOps helps to meet th...
SYS-CON Events announced today that Hitachi Data Systems, a wholly owned subsidiary of Hitachi LTD., will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City. Hitachi Data Systems (HDS) will be featuring the Hitachi Content Platform (HCP) portfolio. This is the industry’s only offering that allows organizations to bring together object storage, file sync and share, cloud storage gateways, and sophisticated search an...
SYS-CON Events announced today that Hitachi, the leading provider the Internet of Things and Digital Transformation, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Hitachi Data Systems, a wholly owned subsidiary of Hitachi, Ltd., offers an integrated portfolio of services and solutions that enable digital transformation through enhanced data management, governance, mobility and analytics. We help globa...
The explosion of new web/cloud/IoT-based applications and the data they generate are transforming our world right before our eyes. In this rush to adopt these new technologies, organizations are often ignoring fundamental questions concerning who owns the data and failing to ask for permission to conduct invasive surveillance of their customers. Organizations that are not transparent about how their systems gather data telemetry without offering shared data ownership risk product rejection, regu...
SYS-CON Events announced today that SoftLayer, an IBM Company, has been named “Gold Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. SoftLayer, an IBM Company, provides cloud infrastructure as a service from a growing number of data centers and network points of presence around the world. SoftLayer’s customers range from Web startups to global enterprises.
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
Five years ago development was seen as a dead-end career, now it’s anything but – with an explosion in mobile and IoT initiatives increasing the demand for skilled engineers. But apart from having a ready supply of great coders, what constitutes true ‘DevOps Royalty’? It’ll be the ability to craft resilient architectures, supportability, security everywhere across the software lifecycle. In his keynote at @DevOpsSummit at 20th Cloud Expo, Jeffrey Scheaffer, GM and SVP, Continuous Delivery Busine...
Bert Loomis was a visionary. This general session will highlight how Bert Loomis and people like him inspire us to build great things with small inventions. In their general session at 19th Cloud Expo, Harold Hannon, Architect at IBM Bluemix, and Michael O'Neill, Strategic Business Development at Nvidia, discussed the accelerating pace of AI development and how IBM Cloud and NVIDIA are partnering to bring AI capabilities to "every day," on-demand. They also reviewed two "free infrastructure" pr...
SYS-CON Events announced today that Super Micro Computer, Inc., a global leader in compute, storage and networking technologies, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Supermicro (NASDAQ: SMCI), the leading innovator in high-performance, high-efficiency server technology, is a premier provider of advanced server Building Block Solutions® for Data Center, Cloud Computing, Enterprise IT, Hadoop/...
NHK, Japan Broadcasting, will feature the upcoming @ThingsExpo Silicon Valley in a special 'Internet of Things' and smart technology documentary that will be filmed on the expo floor between November 3 to 5, 2015, in Santa Clara. NHK is the sole public TV network in Japan equivalent to the BBC in the UK and the largest in Asia with many award-winning science and technology programs. Japanese TV is producing a documentary about IoT and Smart technology and will be covering @ThingsExpo Silicon Val...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
The age of Digital Disruption is evolving into the next era – Digital Cohesion, an age in which applications securely self-assemble and deliver predictive services that continuously adapt to user behavior. Information from devices, sensors and applications around us will drive services seamlessly across mobile and fixed devices/infrastructure. This evolution is happening now in software defined services and secure networking. Four key drivers – Performance, Economics, Interoperability and Trust ...
With billions of sensors deployed worldwide, the amount of machine-generated data will soon exceed what our networks can handle. But consumers and businesses will expect seamless experiences and real-time responsiveness. What does this mean for IoT devices and the infrastructure that supports them? More of the data will need to be handled at - or closer to - the devices themselves.