A lack of care in maintaining equipment, services, and IP address block configurations has put ISPs at imminent risk of distributed denial-of-service attacks
Internet service providers (ISPs) are at imminent risk of large-scale distributed denial-of-service (DDoS) attacks, largely due to a lack of care in managing equipment, services, and the configuration of IP address blocks.
Last year, several Brazilian ISPs faced difficult times as they dealt with DDoS attacks on their infrastructure, a situation that led to numerous posts on social media, as well as coverage in newspapers and on TV shows. Recently, in late February, a new wave of attacks once again hit several ISPs, with numerous reports involving providers in Rio de Janeiro, some of whom have even spoken out publicly, informing customers that they are facing serious problems in providing services due to these attacks.
The victim is not necessarily the target
Despite the disruptions they cause to internet service operations, DDoS attacks targeting ISPs—contrary to popular belief—do not necessarily target the ISPs themselves. In most cases, the goal of hacker groups is to use these companies’ infrastructure to attack their actual targets, which are usually large multinational corporations.
Equipment with inadequate or incorrect configurations, along with human error, are typically factors that facilitate the exploitation and “recruitment” of this infrastructure into the criminal underworld.
During large-scale DDoS attacks, victims are typically hit with a high volume of requests originating from thousands—and sometimes tens of thousands—of different sources, usually spread across the globe.
Mitigation measures and strategies that rely on human effort to identify the sources of attacks become ineffective in the face of hackers’ enormous firepower, since these attacks originate from thousands of different malicious sources that suddenly flood the victim’s infrastructure. That is why it is best to rely on an Anti-DDoS system.
DDoS attacks spread across 181 countries
On the 12th of last month, about two weeks before the new wave of DDoS attacks was made public, Hacknet, an artificial neural network designed to identify hacking activity worldwide, identified and mapped a large network of more than 40,000 servers, spread across 181 countries, that were being used to launch DDoS attacks.
The news was posted on the website and social media accounts of NetSensor, the company that maintains this neural network, along with a link to download the list of IP addresses being used in the attacks, so that security professionals could take preventive measures to protect themselves.
NetSensor reviewed the list of devices that were being exploited, enriched it with additional data, and sent private notifications to the email addresses registered as the contact information for each IP address block.
In Brazil, more than 1,000 companies were involved, resulting in more than 1,600 contact emails, in which NetSensor issued the alert, provided information about the device, and made itself available to answer any further questions.
The results of the notifications were a negative surprise, with things like:
- Email address does not exist;
- Domains that do not exist;
- A “mailbox full” error message, indicating that this is likely a “forgotten” mailbox that has not been read or cleared;
- The people in charge of the blocks responded by saying that they sublease the IP and bear no responsibility for what is being done with it.
- There was even a case in which the person who was supposed to be in charge of the notebook said they hadn’t used it in over two years. As the people in charge, didn’t they ask themselves, “Who’s using this notebook, then?”
The saddest response came from the person in charge of a provider’s server, who simply wrote: “Please remove my email from the list.”
Few companies take this seriously
There were also some companies that responded positively to the alert. Some forwarded the case to the person in charge of the device using that IP address; others requested more information about the case; and still others thanked us for the alert and said they would review the case and take the necessary measures.
Unfortunately, the percentage of companies that took this more serious and professional approach was around 0.5%.
Given this scenario, companies in general need to keep in mind that cybercrime has become much more sophisticated in recent years; it has become highly organized, structured, intelligent, and profitable. Therefore, to be able to confront and defend against these cybercriminals, we must develop techniques and knowledge and make intelligent use of resources that match the level of our attackers. In other words, we must seek out new approaches and technologies capable of helping us defend against emerging threats—threats that we are currently unable to address effectively.
Furthermore, the neglect, incompetence, and negligence we see in relation to networks, equipment, and services can no longer be tolerated. Only then will we have a chance of success in confronting the threats that surround us, coming from the dark side of the internet.
Source: https://www.cisoadvisor.com.br/provedores-de-internet-enfrentam-nova-onda-de-ataques-ddos/
How to Protect Your Internet Service Provider from DDoS Attacks
Just as there are tools used by attackers, we also have tools and methods to protect the service provider. What we need to do is mitigate the attack, which involves protecting the target from DDoS attacks.
Made4it has the right tool for you: Made4Flow!
With Made4Flow, you can detect attacks and take action to protect your provider.
Learn about the benefits of anti-DDoS for internet service providers:
- Protection Against DDoS Attacks: Anti-DDoS helps protect the internet service provider and its customers against DDoS attacks, which can cause service interruptions and damage the provider’s reputation.
- Greater service availability: With DDoS protection, internet service providers can keep their services available to their customers, even during DDoS attacks.
- Improved customer experience: With constant service availability, internet service providers’ customers enjoy a more satisfying experience, which can lead to greater customer loyalty and a reduction in churn (customer cancellation rate).
- Cost savings: Preventing service interruptions and repairing damage caused by DDoS attacks can be costly for internet service providers. Anti-DDoS measures can help save money in the long run by reducing the need for repairs and minimizing downtime.
- Traffic monitoring: Anti-DDoS solutions typically include real-time traffic monitoring capabilities, enabling internet service providers to quickly detect and mitigate threats.