Online attack hits US government Web sites
- 08 July, 2009 11:08
- Comments 1
A botnet comprised of about 50,000 infected computers has been waging a war against U.S. government Web sites and causing headaches for businesses in the U.S. and South Korea.
The attack started Saturday, and security experts have credited it with knocking the U.S. Federal Trade Commission's (FTC's) Web site offline for parts of Monday and Tuesday. Several other government Web sites have also been targeted, including the U.S. Department of Transportation (DOT).
"The DOT has been experiencing network incidents since this past weekend. We are working with the U.S. Computer Emergency Readiness Team [US-CERT] at this time," a DOT spokeswoman said Tuesday.
A spokeswoman for the U.S. Department of the Treasury confirmed that the Treasury's Web site had been hit with a denial-of-service attack. "We're working with our service provider to mitigate the impact," she said.
A spokeswoman for the FTC could not say what caused the outage at that agency's Web site, and the US-CERT did not return calls seeking comment.
Other targets have included banking Web sites in Korea, U.S. Bancorp, the U.S. Secret Service, the U.S. Department of Homeland Security, the U.S. Department of State, the White House, the U.S. Department of Defense, the New York Stock Exchange, the Nasdaq and the Washington Post, according to security researchers studying the incident.
The attack, while powerful, is not particularly sophisticated and appears to be more of a nuisance than a threat to security. It uses a variety of well-known distributed denial of service (DDoS) attacks that try to overwhelm Web sites with useless requests and make them unavailable for legitimate users, security experts say. Most of the targeted sites appeared to be working normally on Tuesday.
Such DDoS attacks are relatively common, but a few things make this week's incident unusual. The botnet code behind the attack does not use typical antivirus evasion techniques and does not appear to have been written by a professional malware writer, according to Joe Stewart, a researcher with SecureWorks who has looked at the code.
On Saturday and Sunday the attack was consuming 20 to 40 gigabytes of bandwidth per second, about 10 times the rate of a typical DDoS attack, one security expert said after being briefed by the US-CERT on Tuesday. "It's the biggest I've seen," said the expert, who asked not to be identified because he was not authorized to discuss the matter. By Tuesday it was averaging about 1.2 gibabytes per second, he said.
Security experts estimate the size of the botnet at somewhere between 30,000 and 60,000 computers.
It is also unusual to see relatively low-profile government Web sites being hit. "Who goes around targeting a site like the FAA or the U.S. Treasury? It's not something that most people would think to attack," Stewart said.
The FTC in the past has brought actions against spammers and Internet fraudsters. Last month it shut down an Internet service provider called Pricewert, which had been associated with botnets, spam and child pornography.
No one knows who is behind the attack, although Stewart said it could have been launched by a single person. "It just seems to me that somebody is mad for some reason at capitalist governments," he said. Security experts say most of the infected machines are located in South Korea, but that doesn't mean the attack originated there.
The fact that the DDoS attack took down government computers is an embarrassment to the U.S., which is working to strengthen the country's cyber-security defenses under President Barack Obama.
"These are very basic attacks and stuff we've seen for a very long time. The scale of these isn't very huge either," said one security expert, who spoke on condition of anonymity because he wasn't authorized to discuss the matter publicly. "It's embarrassing that these sites have been hit for four or five days and they're still being affected. Think of the money that eBay and Amazon would lose in four to five days of this."
Grant Gross in Washington and Nancy Gohring in Seattle contributed to this story.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Phones are distractions during catch-ups
-
Google's Sidewiki lets people post comments about Web pages
-
Leaving your job? Take your data with you
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Social networking, ignorance, and apathy
-
Transforming Your Business by Transforming Your Processes
In this white paper, we build on the “Intelligent Guide to Enterprise BPM: V olume One” in which we described the three entry points where you can begin to build true Enterprise BPM. In this white paper we explain the value of Process T ransformation, the entry point to strategy and design. Successful implementation of Process T ransformation will mean you have successfully documented, standardized, harmonized, managed—as well as analyzed and improved—your business processes. T he next two white papers will detail the other two entry points: Process Automation and Process Intelligence. -
Managing IBM License Complexity
IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on. -
Oracle Exadata - Extreme performance, lowest cost.
As organizations contend with escalating demands for greater quantities of information, more sophisticated data analysis, and a burgeoning user population, Oracle Exadata makes database workloads faster, easier to manage, and less expensive. Oracle Exadata is the world’s first database machine to provide extreme performance for both data warehousing and online transaction processing (OLTP) applications. Read this whitepaper.
-
Windows 7 Visual Quick Tips
-
C++ for Everyone
-
Search Engine Optimization
-
Big C++ Wileyplus/WebCT Standalone Card
-
Quick Recipes on Symbian OS - Mastering C++ Smartphone Development
-
Big C++ Desktop Edition
-
Iphone SDK 3 Programming - Advanced Mobile Development for Apple Iphone and iPod Touch
-
Adobe Premiere 6 Bible
-
Techniques of Prolog Programming with Implementation of Logical Negation and Quantified Goals








Comments
THANHNGUYEN41
塾
五反田 賃貸
ケータリング 東京
妊娠 腹痛
結婚式
<a href="http://www.nohvas-juku.com/">塾</a>
<a href="http://navi.mrd330.co.jp/tokyo-ch/station/gotanda.html">五反田 賃貸</a>
<a href="http://www.aporte.net/">ケータリング 東京</a>
<a href="http://www.internethospital.net/login/index-net.html">妊娠 腹痛</a>
<a href="http://www.kekkon-j.com/manual/fashion/">結婚式 服装</a>
<a href="http://www.kinyutensyoku.com/ma.html">M&A 転職</a>
<a href="http://www.jhct.co.jp/">小金井 不動産</a>
<a href="http://www.stylful.jp/ec/weddinggift/">引き出物</a>
<a href="http://www.634sangyo.co.jp/">八王子 マンション</a>
<a href="http://www.jasac.com/program/undergraduate/aus/">オーストラリア大学</a>
<a href="http://www.88zaisan.com/manshitu.html">アパートマンション 満室経営</a>
<a href="http://fairwaygolf.jp/">ゴルフツアー</a>
<a href="http://www.e-omisega.com/">景品 子供</a>
<a href="http://withedesign.jp/">リフォーム会社</a>
<a href="http://www.ysd-pack.co.jp/">プラスチックトレイ</a>
<a href="http://www.rshop.ne.jp/sy/aloeveragel.html">アロエベラジュース</a>
<a href="http://www.tealla.jp/">カラーコンタクト 度あり</a>
<a href="http://www.c21-yokohama-chintai.co.jp/">センター北 不動産</a>
<a href="http://www.suzuki-gyosei.jp/">相続 相談</a>
<a href="http://www.fair-medical.jp/">中古医療機器 処分</a>
<a href="http://www.bridalstory.net/">結婚相談所 東京</a>
<a href="http://www.nikkeigolf.co.jp/">ゴルフ会員権</a>
<a href="http://www.karigo.net/">バーチャルオフィス</a>
<a href="http://www.biyoushika.jp/">インプラント 神奈川</a>
<a href="http://www.ihc-live.com/">英会話 オンライン</a>
<a href="http://www.ihcway.com/station/kanagawa/">英会話 神奈川</a>
<a href="http://www.ihcway.com/cafe/">英会話 個人レッスン</a>
<a href="http://reform-style.net/">リフォーム会社</a>
<a href="http://www.create-trunk.jp/">トランクルーム</a>
<a href="http://www.garden1.jp/">ガーデンファニチャー</a>
<a href="http://www.mancapital.co.jp/">人材派遣</a>
<a href="http://www.u-doctor.com/rinnai_top.htm">リンナイ</a>
<a href="https://www.aeonnetcampus.com/internet/kids/">こども英会話</a>
<a href="http://www.e-fil.co.jp/">タオル</a>
<a href="http://drandy-cosme.com/SHOP/002.html">アルギニンサプリメント</a>
<a href="http://www.sample-net.com/?action_user_serviceList=t">飲料水</a>
<a href="http://hirakawajimusyo.jp/">行政書士 横浜市</a>
<a href="http://www.platinumstyle.co.jp/">結婚式二次会 プロデュース</a>
<a href="http://www.reallove.to/">結婚相談 東京</a>
<a href="http://www.uenogift.jp/">三和</a>
<a href="http://www.ash-planning.co.jp/">店舗設計 関西</a>
<a href="http://www.good-job-hair.com/">女性用かつら</a>
<a href="http://bunkyo-life.jp/">文京区 賃貸</a>
<a href="http://www.orgpalm.com/custom/print.html">Tシャツ プリント</a>
<a href="http://www.mackenzie.co.jp/hadano">秦野 建築</a>
<a href="http://www.claudia.co.jp/tuhan/goods/health/alpha_gpc/">身長を伸ばす</a>
<a href="http://www.offix-data.co.jp/">賃貸事務所</a>
<a href="http://www.rmtplusone.com/atlantica/">アトランティカRMT</a>
<a href="http://www.hirochi.co.jp/">ハーレー</a>
<a href="http://www.tmsp.jp/doc1+index.id+1.htm">商標出願</a>
<a href="http://www.bse.jp/">バイク便</a>
<a href="http://www.tabitama.co.jp/yado/">大阪 ホテル</a>
<a href="http://www.ii-life.co.jp/html/fc/index.html">介護フランチャイズ</a>
<a href="http://www.atopinavi.com/">アトピー性皮膚炎</a>
<a href="http://www.kubire.jp/site/index.html">ブライダルエステ</a>
<a href="http://www.voat.co.jp/audition/">歌手オーディション</a>
<a href="http://www.myhome-rd.co.jp/">埼玉 不動産</a>
<a href="http://www.ec-life.co.jp/garage/">ガレージ</a>
Post new comment