‘No indication’ devices from Singapore contributed to US cyberattack: CSA
By Kevin Kwang Posted 27 Oct 2016 13:39 Updated 27 Oct 2016 13:40
SINGAPORE: There is no indication that devices from Singapore contributed to the attack against US-based domain name service provider Dyn, which resulted in Web services like Twitter, Spotify and Reddit experiencing downtime, the Cyber Security Agency of Singapore (CSA) said on Wednesday (Oct 26).
In its reply to queries by Channel NewsAsia, a CSA spokesperson said there is a wide range of Internet-connected devices manufactured from various countries on the market, and that any of these devices could be commandeered by hackers anywhere in the world. These cybercriminals can, in turn, direct the zombie devices to take down a targeted site by flooding it with Web traffic.
Dyn on Wednesday shed more light on the Oct 21 attack on its managed DNS infrastructure, with the company’s EVP of Product Scott Hilton stating in a blogpost that the attack was “complex and sophisticated”, and confirming that the Mirai botnet was the primary source of malicious attack traffic.
Mirai is a malware that targets insecure Internet of Things (IoT) devices such as webcams and home routers, and the source code for the malware was released on the open Web earlier in October before the Dyn attack took place.
Chinese manufacturer Hangzhou Xiongmai was fingered as the maker of compromised webcams used in the Dyn attack, and said it would recall as many as 10,000 infected devices as a result. Mr Li Yuexin, Xiongmai’s marketing director, told Reuters on Tuesday that the company would recall the first few batches of surveillance cameras made in 2014 that monitor rooms or shops for personal use.
Threat research company Flashpoint had actually flagged the company as early as Oct 7, after similar large-scale DDoS attacks were conducted on security research Brian Kreb’s blog and French Web hosting company OVH. Flashpoint researchers said then that Xiongmai sells white-labelled DVRs, IP cameras and software to other vendors who then use these in their own products.
“Altogether, over 500,000 devices on public IPs around the world appear susceptible to this vulnerability,” according to the security note.
Local telco StarHub had on Wednesday also identified such compromised devices as the cause for DDoS attacks that resulted in two broadband outages it suffered on Oct 22 and Oct 24. It stopped short of linking its downtime with that of the attack on Dyn.
The attack on StarHub was the first of that nature on Singapore’s infrastructure, according to the CSA and Infocomm Media Development Authority.
- CNA/cy
- wong chee tat :)
Showing posts with label ddos. Show all posts
Showing posts with label ddos. Show all posts
Thursday, October 27, 2016
Australia e-census attack 'incorrectly' attributed to Singapore-based router: CSA
Australia e-census attack 'incorrectly' attributed to Singapore-based router: CSA
Posted 25 Oct 2016 19:54 Updated 25 Oct 2016 20:00
SINGAPORE: The Cyber Security Agency of Singapore (CSA) on Tuesday (Oct 25) refuted reports that cyber attacks which shut down a national census in Australia were launched through a router based in Singapore.
In a statement, the CSA said that it was "surprised at media reports on IBM Australia’s assertions that the majority of international traffic which caused the crash of the Australian Bureau of Statistics (ABS) Census website originated from Singapore."
International Business Machines Corp (IBM) was the lead contractor for the five-yearly Aug 9 household survey by the ABS, which went offline that day after four distributed denial of service (DDoS) attacks, caused by the website being flooded with clicks.
At a Senate inquiry into the matter, IBM Australia and New Zealand managing director Kerry Purcell said that the attacks were launched through a router in Singapore. He blamed Australian ISP Vocus Communications, a subcontractor of Nextgen Networks, for failing to shut it down.
Singapore's CSA questioned IBM's assertion in its statement. "For matters of such nature, it is usual practice for national Computer Emergency Readiness Teams (CERTs) to make inquiries and seek assistance from one another," the agency said.
"In this instance, our SingCERT was not informed of any such attack by CERT Australia. We were also not approached at any point. As such, it is strange that IBM Australia reached such a conclusion."
The agency added that it has contacted CERT Australia for more information, and that it was ready to assist the Australian authorities where required. "According to CERT Australia, some internal ABS infrastructure was hosted in Singapore. There may have been possible misunderstanding in the news reporting of this issue, which incorrectly attributed the DDoS attack source to Singapore."
IBM said on Tuesday that it plans to compensate the Australian government for the "malicious" cyber-attacks.
The breach embarrassed a government which has sought to impress voters with its cybersecurity credentials and plans to trial online elections. The census is already controversial because of privacy concerns.
In a written submission to the inquiry, IBM said its preferred anti-DDoS measure, which it calls "Island Australia", involves "geoblocking", or getting the company's ISPs to shut down offshore traffic coming into the country.
In a written submission to the inquiry, Nextgen said IBM told it about "Island Australia" six days before the census website went live in July, and that IBM declared a test of the strategy four days before the census a success.
It said Nextgen followed IBM's instructions, but noted that IBM rejected Nextgen's offer of additional anti-DDoS detection measures.
Vocus said in a submission that it told Nextgen the week before the census that it "did not provide geoblocking" and that "Vocus was in fact requested to disable its DDoS protection product covering the e-Census IP space".
It did not specify who gave that instruction.
ABS chief statistician David Kalisch said he was confident IBM could deliver on its A$10 million ($7.63 million) contract based on "the comments and exhortations that IBM had made to the ABS about the importance of this work" beforehand.
- CNA/Reuters/nc
- wong chee tat :)
Posted 25 Oct 2016 19:54 Updated 25 Oct 2016 20:00
SINGAPORE: The Cyber Security Agency of Singapore (CSA) on Tuesday (Oct 25) refuted reports that cyber attacks which shut down a national census in Australia were launched through a router based in Singapore.
In a statement, the CSA said that it was "surprised at media reports on IBM Australia’s assertions that the majority of international traffic which caused the crash of the Australian Bureau of Statistics (ABS) Census website originated from Singapore."
International Business Machines Corp (IBM) was the lead contractor for the five-yearly Aug 9 household survey by the ABS, which went offline that day after four distributed denial of service (DDoS) attacks, caused by the website being flooded with clicks.
At a Senate inquiry into the matter, IBM Australia and New Zealand managing director Kerry Purcell said that the attacks were launched through a router in Singapore. He blamed Australian ISP Vocus Communications, a subcontractor of Nextgen Networks, for failing to shut it down.
Singapore's CSA questioned IBM's assertion in its statement. "For matters of such nature, it is usual practice for national Computer Emergency Readiness Teams (CERTs) to make inquiries and seek assistance from one another," the agency said.
"In this instance, our SingCERT was not informed of any such attack by CERT Australia. We were also not approached at any point. As such, it is strange that IBM Australia reached such a conclusion."
The agency added that it has contacted CERT Australia for more information, and that it was ready to assist the Australian authorities where required. "According to CERT Australia, some internal ABS infrastructure was hosted in Singapore. There may have been possible misunderstanding in the news reporting of this issue, which incorrectly attributed the DDoS attack source to Singapore."
IBM said on Tuesday that it plans to compensate the Australian government for the "malicious" cyber-attacks.
The breach embarrassed a government which has sought to impress voters with its cybersecurity credentials and plans to trial online elections. The census is already controversial because of privacy concerns.
In a written submission to the inquiry, IBM said its preferred anti-DDoS measure, which it calls "Island Australia", involves "geoblocking", or getting the company's ISPs to shut down offshore traffic coming into the country.
In a written submission to the inquiry, Nextgen said IBM told it about "Island Australia" six days before the census website went live in July, and that IBM declared a test of the strategy four days before the census a success.
It said Nextgen followed IBM's instructions, but noted that IBM rejected Nextgen's offer of additional anti-DDoS detection measures.
Vocus said in a submission that it told Nextgen the week before the census that it "did not provide geoblocking" and that "Vocus was in fact requested to disable its DDoS protection product covering the e-Census IP space".
It did not specify who gave that instruction.
ABS chief statistician David Kalisch said he was confident IBM could deliver on its A$10 million ($7.63 million) contract based on "the comments and exhortations that IBM had made to the ABS about the importance of this work" beforehand.
- CNA/Reuters/nc
- wong chee tat :)
Labels:
2016,
computer network,
computer networking,
ddos,
dos,
IBM,
Internet outage,
market,
mobile network,
network,
oct,
opportunities,
outages
Broadband service outages due to DDoS attacks: StarHub
Broadband service outages due to DDoS attacks: StarHub
Posted 25 Oct 2016 15:36 Updated 25 Oct 2016 23:07
SINGAPORE: The two recent broadband service outages that hit StarHub were the result of "intentional and likely malicious attacks" on its servers, the telco confirmed on Tuesday (Oct 25), adding that the attacks were "unprecedented in scale, nature and complexity".
In a media statement, StarHub said: "We have completed inspecting and analysing network logs from the home broadband incidents on Oct 22 and Oct 24 and we are now able to confirm that we had experienced intentional and likely malicious distributed denial-of-service (DDoS) attacks on our domain name servers (DNS).
"These two recent attacks that we experienced were unprecedented in scale, nature and complexity," it said.
Starhub said that the DDoS attacks caused temporary web connection issue for some of its home broadband customers. "On both occasions, we mitigated the attacks by filtering unwanted traffic and increasing our DNS capacity, and restored service within two hours. No impact was observed on the rest of our services, and the security of our customers’ information was not compromised."
The broadband service provider said it would continue to stay vigilant against possible follow-up DDoS attempts, and is working closely with the authorities to determine intent and source of these two DDoS attacks.
Earlier on Tuesday, the Cyber Security Agency (CSA) and the Infocomm Media Development Authority (IMDA) said that the possibility of a DDoS attack could not be ruled out, and noted that StarHub's outages came on the heels of Friday’s attack against the US-based domain name system service provider Dyn.
StarHub had earlier said it detected a "spike in data traffic" coming into its domain name servers (DNS) that temporarily affected the Web connection for some of its home broadband customers during the time of the outage.
A DNS is a database that translates Web addresses, such as www.nameofwebsite.com, into machine readable sets of digits for customers to view websites on their computers.
"When a DNS is not operating optimally, customers may face difficulty in accessing the Internet," the telco said.
After detecting the sudden increase in traffic to the servers, StarHub said it immediately started filtering the unwanted traffic and added DNS capacity to manage the "huge increase in traffic load". As a result, some customers temporarily faced intermittent broadband access, it said.
The telco added that there was no impact on its mobile broadband, enterprise and home voice services, and the security of customers’ information was not compromised.
According to StarHub, the home broadband service for affected customers was fully restored at about 11.25pm on Monday.
The company said that initial investigations pointed to similarities between the outage on Monday and the first incident last Saturday.
- CNA/mz/ek
- wong chee tat :)
Posted 25 Oct 2016 15:36 Updated 25 Oct 2016 23:07
SINGAPORE: The two recent broadband service outages that hit StarHub were the result of "intentional and likely malicious attacks" on its servers, the telco confirmed on Tuesday (Oct 25), adding that the attacks were "unprecedented in scale, nature and complexity".
In a media statement, StarHub said: "We have completed inspecting and analysing network logs from the home broadband incidents on Oct 22 and Oct 24 and we are now able to confirm that we had experienced intentional and likely malicious distributed denial-of-service (DDoS) attacks on our domain name servers (DNS).
"These two recent attacks that we experienced were unprecedented in scale, nature and complexity," it said.
Starhub said that the DDoS attacks caused temporary web connection issue for some of its home broadband customers. "On both occasions, we mitigated the attacks by filtering unwanted traffic and increasing our DNS capacity, and restored service within two hours. No impact was observed on the rest of our services, and the security of our customers’ information was not compromised."
The broadband service provider said it would continue to stay vigilant against possible follow-up DDoS attempts, and is working closely with the authorities to determine intent and source of these two DDoS attacks.
Earlier on Tuesday, the Cyber Security Agency (CSA) and the Infocomm Media Development Authority (IMDA) said that the possibility of a DDoS attack could not be ruled out, and noted that StarHub's outages came on the heels of Friday’s attack against the US-based domain name system service provider Dyn.
StarHub had earlier said it detected a "spike in data traffic" coming into its domain name servers (DNS) that temporarily affected the Web connection for some of its home broadband customers during the time of the outage.
A DNS is a database that translates Web addresses, such as www.nameofwebsite.com, into machine readable sets of digits for customers to view websites on their computers.
"When a DNS is not operating optimally, customers may face difficulty in accessing the Internet," the telco said.
After detecting the sudden increase in traffic to the servers, StarHub said it immediately started filtering the unwanted traffic and added DNS capacity to manage the "huge increase in traffic load". As a result, some customers temporarily faced intermittent broadband access, it said.
The telco added that there was no impact on its mobile broadband, enterprise and home voice services, and the security of customers’ information was not compromised.
According to StarHub, the home broadband service for affected customers was fully restored at about 11.25pm on Monday.
The company said that initial investigations pointed to similarities between the outage on Monday and the first incident last Saturday.
- CNA/mz/ek
- wong chee tat :)
Labels:
2016,
computer network,
computer networking,
ddos,
dns,
dos,
Google Public DNS service,
Internet outage,
market,
mobile network,
network,
oct,
opendns,
opportunities,
outages,
router,
StarHub
Possibility of DDoS attack on StarHub broadband service cannot be ruled out: IMDA
Possibility of DDoS attack on StarHub broadband service cannot be ruled out: IMDA
Posted 25 Oct 2016 18:09 Updated 25 Oct 2016 22:21
SINGAPORE: Authorities are not ruling out the possibility of a Distributed Denial of Service (DDoS) attack in the two outages that telco StarHub's broadband service saw in the space of two days.
In a joint statement to the media on Tuesday (Oct 25), the Cyber Security Agency (CSA) and the Infocomm Media Development Authority (IMDA) said: "We have been paying close attention to developments as it happened on the heels of Friday’s attack against the US-based domain name system service provider, Dyn. We cannot rule out the possibility that this was a DDoS attack."
Earlier on Tuesday, StarHub said Monday's outage came after it detected a "spike in data traffic" coming into its domain name servers. The telco said it is currently investigating the root cause, including whether the spike in traffic was malicious in intent.
"What is important now is for StarHub to determine the root cause of the problem and prevent a recurrence," said IMDA and CSA in their joint statement.
"IMDA is working closely with StarHub to investigate the matter and strengthen its infrastructure and processes.
OTHER TELCOS ADVISED TO STEP UP DEFENCES
In the statement, IMDA said it also advised the other telcos to step up their defences in case there are similar disruptions to their systems.
Responding to queries from Channel NewsAsia's, Singtel said it has measures in place to safeguard its network.
“We did not observe any abnormal traffic trends over the past weekend, but will continue to monitor our networks closely. We have a robust monitoring system and resilient protection mechanisms in place to safeguard our networks,” a spokesperson told Channel NewsAsia.
M1 said it is "aware of the recent cyber-attacks and is on alert".
"We have made significant investments to defend our systems against cyber-attacks, including DDoS attacks," said Mr Chua Hian Hou, assistant general manager of corporate communications at M1.
In the joint statement, CSA added that it is "studying and addressing the risks of DDoS attacks on our communications systems, as well as the measures to mitigate the impact of such attacks if they happen."
CSA added that it would also reach out to educate the public and businesses on the need to properly secure their systems.
- CNA/dt
- wong chee tat :)
Posted 25 Oct 2016 18:09 Updated 25 Oct 2016 22:21
SINGAPORE: Authorities are not ruling out the possibility of a Distributed Denial of Service (DDoS) attack in the two outages that telco StarHub's broadband service saw in the space of two days.
In a joint statement to the media on Tuesday (Oct 25), the Cyber Security Agency (CSA) and the Infocomm Media Development Authority (IMDA) said: "We have been paying close attention to developments as it happened on the heels of Friday’s attack against the US-based domain name system service provider, Dyn. We cannot rule out the possibility that this was a DDoS attack."
Earlier on Tuesday, StarHub said Monday's outage came after it detected a "spike in data traffic" coming into its domain name servers. The telco said it is currently investigating the root cause, including whether the spike in traffic was malicious in intent.
"What is important now is for StarHub to determine the root cause of the problem and prevent a recurrence," said IMDA and CSA in their joint statement.
"IMDA is working closely with StarHub to investigate the matter and strengthen its infrastructure and processes.
OTHER TELCOS ADVISED TO STEP UP DEFENCES
In the statement, IMDA said it also advised the other telcos to step up their defences in case there are similar disruptions to their systems.
Responding to queries from Channel NewsAsia's, Singtel said it has measures in place to safeguard its network.
“We did not observe any abnormal traffic trends over the past weekend, but will continue to monitor our networks closely. We have a robust monitoring system and resilient protection mechanisms in place to safeguard our networks,” a spokesperson told Channel NewsAsia.
M1 said it is "aware of the recent cyber-attacks and is on alert".
"We have made significant investments to defend our systems against cyber-attacks, including DDoS attacks," said Mr Chua Hian Hou, assistant general manager of corporate communications at M1.
In the joint statement, CSA added that it is "studying and addressing the risks of DDoS attacks on our communications systems, as well as the measures to mitigate the impact of such attacks if they happen."
CSA added that it would also reach out to educate the public and businesses on the need to properly secure their systems.
- CNA/dt
- wong chee tat :)
Labels:
2016,
computer network,
computer networking,
ddos,
dns,
dos,
Google Public DNS service,
Internet outage,
M1,
market,
mobile network,
network,
oct,
opendns,
opportunities,
outages,
router,
SingTel,
StarHub
Broadband service outages due to DDoS attacks: StarHub
Broadband service outages due to DDoS attacks: StarHub
Posted 25 Oct 2016 15:36 Updated 25 Oct 2016 23:07
SINGAPORE: The two recent broadband service outages that hit StarHub were the result of "intentional and likely malicious attacks" on its servers, the telco confirmed on Tuesday (Oct 25), adding that the attacks were "unprecedented in scale, nature and complexity".
In a media statement, StarHub said: "We have completed inspecting and analysing network logs from the home broadband incidents on Oct 22 and Oct 24 and we are now able to confirm that we had experienced intentional and likely malicious distributed denial-of-service (DDoS) attacks on our domain name servers (DNS).
"These two recent attacks that we experienced were unprecedented in scale, nature and complexity," it said.
Starhub said that the DDoS attacks caused temporary web connection issue for some of its home broadband customers. "On both occasions, we mitigated the attacks by filtering unwanted traffic and increasing our DNS capacity, and restored service within two hours. No impact was observed on the rest of our services, and the security of our customers’ information was not compromised."
The broadband service provider said it would continue to stay vigilant against possible follow-up DDoS attempts, and is working closely with the authorities to determine intent and source of these two DDoS attacks.
Earlier on Tuesday, the Cyber Security Agency (CSA) and the Infocomm Media Development Authority (IMDA) said that the possibility of a DDoS attack could not be ruled out, and noted that StarHub's outages came on the heels of Friday’s attack against the US-based domain name system service provider Dyn.
StarHub had earlier said it detected a "spike in data traffic" coming into its domain name servers (DNS) that temporarily affected the Web connection for some of its home broadband customers during the time of the outage.
A DNS is a database that translates Web addresses, such as www.nameofwebsite.com, into machine readable sets of digits for customers to view websites on their computers.
"When a DNS is not operating optimally, customers may face difficulty in accessing the Internet," the telco said.
After detecting the sudden increase in traffic to the servers, StarHub said it immediately started filtering the unwanted traffic and added DNS capacity to manage the "huge increase in traffic load". As a result, some customers temporarily faced intermittent broadband access, it said.
The telco added that there was no impact on its mobile broadband, enterprise and home voice services, and the security of customers’ information was not compromised.
According to StarHub, the home broadband service for affected customers was fully restored at about 11.25pm on Monday.
The company said that initial investigations pointed to similarities between the outage on Monday and the first incident last Saturday.
- CNA/mz/ek
- wong chee tat :)
Posted 25 Oct 2016 15:36 Updated 25 Oct 2016 23:07
SINGAPORE: The two recent broadband service outages that hit StarHub were the result of "intentional and likely malicious attacks" on its servers, the telco confirmed on Tuesday (Oct 25), adding that the attacks were "unprecedented in scale, nature and complexity".
In a media statement, StarHub said: "We have completed inspecting and analysing network logs from the home broadband incidents on Oct 22 and Oct 24 and we are now able to confirm that we had experienced intentional and likely malicious distributed denial-of-service (DDoS) attacks on our domain name servers (DNS).
"These two recent attacks that we experienced were unprecedented in scale, nature and complexity," it said.
Starhub said that the DDoS attacks caused temporary web connection issue for some of its home broadband customers. "On both occasions, we mitigated the attacks by filtering unwanted traffic and increasing our DNS capacity, and restored service within two hours. No impact was observed on the rest of our services, and the security of our customers’ information was not compromised."
The broadband service provider said it would continue to stay vigilant against possible follow-up DDoS attempts, and is working closely with the authorities to determine intent and source of these two DDoS attacks.
Earlier on Tuesday, the Cyber Security Agency (CSA) and the Infocomm Media Development Authority (IMDA) said that the possibility of a DDoS attack could not be ruled out, and noted that StarHub's outages came on the heels of Friday’s attack against the US-based domain name system service provider Dyn.
StarHub had earlier said it detected a "spike in data traffic" coming into its domain name servers (DNS) that temporarily affected the Web connection for some of its home broadband customers during the time of the outage.
A DNS is a database that translates Web addresses, such as www.nameofwebsite.com, into machine readable sets of digits for customers to view websites on their computers.
"When a DNS is not operating optimally, customers may face difficulty in accessing the Internet," the telco said.
After detecting the sudden increase in traffic to the servers, StarHub said it immediately started filtering the unwanted traffic and added DNS capacity to manage the "huge increase in traffic load". As a result, some customers temporarily faced intermittent broadband access, it said.
The telco added that there was no impact on its mobile broadband, enterprise and home voice services, and the security of customers’ information was not compromised.
According to StarHub, the home broadband service for affected customers was fully restored at about 11.25pm on Monday.
The company said that initial investigations pointed to similarities between the outage on Monday and the first incident last Saturday.
- CNA/mz/ek
- wong chee tat :)
Labels:
2016,
computer network,
computer networking,
ddos,
dns,
dos,
dyn,
Google Public DNS service,
Internet outage,
market,
mobile network,
network,
oct,
opendns,
opportunities,
outages,
router,
StarHub
Compromised home devices triggered broadband outages: StarHub
Compromised home devices triggered broadband outages: StarHub
By Kevin Kwang Posted 26 Oct 2016 19:10 Updated 27 Oct 2016 08:56
SINGAPORE: Web-connected devices bought by StarHub subscribers were the cause of the "illegitimate traffic" that resulted in the distributed denial of service (DDoS) the telco suffered twice in two days, said StarHub's chief technology officer (CTO) Mock Pak Lum on Wednesday (Oct 26).
In a media briefing, Mr Mock said affected devices such as broadband routers and webcams were responsible for the spike in Web traffic the telco saw last Saturday and Monday nights.
However, he did not disclose how many devices or IP addresses were compromised, or what was the exact volume in the spike in Web traffic its domain name server (DNS) farms had to handle in a short space of time.
The illegitimate traffic to the DNS resulted in an overload that disrupted Web connection for "some" broadband users, Mr Mock said. "Not everyone was affected," he added, saying that some users would have gotten to their desired webpage if they had waited long enough.
As remedial action, the telco said it has increased DNS capacity by 400 per cent since Saturday, and is also implementing traffic filtering and source tracing to identify the source of Web traffic surges.
It is also looking to deploy its technical team - HubTroopers - to subscribers identified with compromised devices to help them troubleshoot. This could either be done at their homes or, with their permission, taken back to StarHub for further investigation.
That said, the CTO said his team is working to scrub through the logs to see if the traffic spike was linked to the attack on US-based Dyn DNS. He noted that there are similarities in that compromised connected home devices were used to conduct the attack, but that it was too early to draw any conclusion.
He also could not comment as to why only StarHub was attacked by the compromised devices, while other Internet service providers were not affected.
StarHub is working with the Cyber Security Agency of Singapore (CSA) in terms of sharing information from its investigations, he added.
In the meantime, Mr Mock stressed that "everyone has a role to play in cybersecurity". "The reward is now too huge" for cybercriminals and the online threat will be "prevalent for a long time to come", the CTO said.
He suggested that consumers only get devices that are "reputable", remember to change the default passwords and set up the necessary defences such as firewalls after buying the devices.
He also cautioned against blindly opening up Web links sent from friends via emails, for instance, as this could potentially lead to malware being downloaded into the device without the user's knowledge.
DDoS ATTACKS LIKELY TO BE MORE COMMON: EXPERTS
The CSA and the Infocomm Media Development Authority (IMDA) said in a joint statement that the DDoS attacks are the first such incident against Singapore's telco infrastructure, and reiterated that they are working "closely" with StarHub to investigate the matter.
Commenting on StarHub's announcement, Mr John Lim, course manager at Nanyang Polytechnic's School of Information Technology, told Channel NewsAsia that he was not surprised that compromised embedded devices were used to stage the DDoS attacks.
He said that PCs and Macs have become much more secure today, but this is not so for devices such as webcams or routers.
"You cannot just install antivirus on these devices," Mr Lim said.
Additionally, consumers can now shop for such connected devices from e-commerce sites such as Taobao, and many times these are brands that are not known here and there is little to no information on the kind of defences manufacturers have installed, he said.
With the proliferation of these Web-connected devices, Mr Lim said he "won't be surprised if there will be other similar attacks that might affect the other two telcos" in the future.
Other experts Channel NewsAsia spoke to concurred, with one pointing to the gaining popularity of the Internet of Things.
"There's research done that 50 billion devices will be connected in 2020. Just imagine: 50 billion (devices) attacking your organisation," said Mr Vincent Loy, Asia Pacific Cyber & Financial Crime Leader at PwC Singapore.
Mr Loy too added that many devices are not built with security in mind.
"They were built to do a certain function; security was not part of it; they do not have password control. They do not have security control, they do not have a log in or back up. The Government and private sector need to work together to come up with a solution in coming up with security by design," Mr Loy said.
Mr Stephen Dane, a managing director at Cisco Systems (HK), pointed to the need for companies to pay more attention to security.
"It's really important to design a network and your infrastructure with high availability in mind, to ensure that not all your eggs are in one basket when it comes to protecting or providing data and holding records on behalf of customers; or in fact, having a website that's associated with just one domain name server," he said.
"It's important to build that resiliency into your infrastructure and ensure that there's high availability as much as possible, so that you are ensuring that the target is distributed as much as possible and therefore the risk is reduced," he added.
Additional reporting by Alice Chia.
- CNA/kk/dl
- wong chee tat :)
By Kevin Kwang Posted 26 Oct 2016 19:10 Updated 27 Oct 2016 08:56
SINGAPORE: Web-connected devices bought by StarHub subscribers were the cause of the "illegitimate traffic" that resulted in the distributed denial of service (DDoS) the telco suffered twice in two days, said StarHub's chief technology officer (CTO) Mock Pak Lum on Wednesday (Oct 26).
In a media briefing, Mr Mock said affected devices such as broadband routers and webcams were responsible for the spike in Web traffic the telco saw last Saturday and Monday nights.
However, he did not disclose how many devices or IP addresses were compromised, or what was the exact volume in the spike in Web traffic its domain name server (DNS) farms had to handle in a short space of time.
The illegitimate traffic to the DNS resulted in an overload that disrupted Web connection for "some" broadband users, Mr Mock said. "Not everyone was affected," he added, saying that some users would have gotten to their desired webpage if they had waited long enough.
As remedial action, the telco said it has increased DNS capacity by 400 per cent since Saturday, and is also implementing traffic filtering and source tracing to identify the source of Web traffic surges.
It is also looking to deploy its technical team - HubTroopers - to subscribers identified with compromised devices to help them troubleshoot. This could either be done at their homes or, with their permission, taken back to StarHub for further investigation.
That said, the CTO said his team is working to scrub through the logs to see if the traffic spike was linked to the attack on US-based Dyn DNS. He noted that there are similarities in that compromised connected home devices were used to conduct the attack, but that it was too early to draw any conclusion.
He also could not comment as to why only StarHub was attacked by the compromised devices, while other Internet service providers were not affected.
StarHub is working with the Cyber Security Agency of Singapore (CSA) in terms of sharing information from its investigations, he added.
In the meantime, Mr Mock stressed that "everyone has a role to play in cybersecurity". "The reward is now too huge" for cybercriminals and the online threat will be "prevalent for a long time to come", the CTO said.
He suggested that consumers only get devices that are "reputable", remember to change the default passwords and set up the necessary defences such as firewalls after buying the devices.
He also cautioned against blindly opening up Web links sent from friends via emails, for instance, as this could potentially lead to malware being downloaded into the device without the user's knowledge.
DDoS ATTACKS LIKELY TO BE MORE COMMON: EXPERTS
The CSA and the Infocomm Media Development Authority (IMDA) said in a joint statement that the DDoS attacks are the first such incident against Singapore's telco infrastructure, and reiterated that they are working "closely" with StarHub to investigate the matter.
Commenting on StarHub's announcement, Mr John Lim, course manager at Nanyang Polytechnic's School of Information Technology, told Channel NewsAsia that he was not surprised that compromised embedded devices were used to stage the DDoS attacks.
He said that PCs and Macs have become much more secure today, but this is not so for devices such as webcams or routers.
"You cannot just install antivirus on these devices," Mr Lim said.
Additionally, consumers can now shop for such connected devices from e-commerce sites such as Taobao, and many times these are brands that are not known here and there is little to no information on the kind of defences manufacturers have installed, he said.
With the proliferation of these Web-connected devices, Mr Lim said he "won't be surprised if there will be other similar attacks that might affect the other two telcos" in the future.
Other experts Channel NewsAsia spoke to concurred, with one pointing to the gaining popularity of the Internet of Things.
"There's research done that 50 billion devices will be connected in 2020. Just imagine: 50 billion (devices) attacking your organisation," said Mr Vincent Loy, Asia Pacific Cyber & Financial Crime Leader at PwC Singapore.
Mr Loy too added that many devices are not built with security in mind.
"They were built to do a certain function; security was not part of it; they do not have password control. They do not have security control, they do not have a log in or back up. The Government and private sector need to work together to come up with a solution in coming up with security by design," Mr Loy said.
Mr Stephen Dane, a managing director at Cisco Systems (HK), pointed to the need for companies to pay more attention to security.
"It's really important to design a network and your infrastructure with high availability in mind, to ensure that not all your eggs are in one basket when it comes to protecting or providing data and holding records on behalf of customers; or in fact, having a website that's associated with just one domain name server," he said.
"It's important to build that resiliency into your infrastructure and ensure that there's high availability as much as possible, so that you are ensuring that the target is distributed as much as possible and therefore the risk is reduced," he added.
Additional reporting by Alice Chia.
- CNA/kk/dl
- wong chee tat :)
Labels:
2016,
computer network,
computer networking,
ddos,
dns,
dos,
dyn,
Google Public DNS service,
Internet outage,
market,
mobile network,
network,
oct,
opendns,
opportunities,
outages,
router,
StarHub
DDoS attack on StarHub first of its kind on Singapore's telco infrastructure: CSA, IMDA
DDoS attack on StarHub first of its kind on Singapore's telco infrastructure: CSA, IMDA
Posted 26 Oct 2016 21:20 Updated 26 Oct 2016 23:35
SINGAPORE: The Distributed Denial of Service (DDoS) attacks on StarHub’s broadband network were the first of that nature on Singapore's telco infrastructure, the Cyber Security Agency of Singapore (CSA) and Infocomm Media Development Authority (IMDA) said on Wednesday evening (Oct 26).
This comes after the telco revealed in a media briefing on Wednesday that compromised devices such as webcams and routers owned by its customers led to the DDoS attacks.
In a joint statement, CSA and IMDA said attacks on Domain Name Services (DNS), as seen in StarHub’s case, are “generally rare”, “although the latest Dyn incident in US has shown that it is surfacing as an emerging trend”.
The agencies added that in DDoS attacks, attackers usually scan for vulnerable Internet-connected devices commonly known as "botnet" and employ a list of techniques - such as password cracking - to gain access to them.
“Any Internet-connected device, from WiFi routers to printers to CCTVs, can inadvertently be part of a network of ‘bots’ that can be activated to attack other systems,” CSA and IMDA said, adding that there is no foolproof solution as digital systems are increasingly connected.
As such, telcos must ensure they have “resilient and robust” systems, and put in place measures to quickly detect and respond to such attacks, so as to avoid disruption of services to their subscribers, CSA and IMDA added.
They reiterated that they are working “closely” with StarHub to investigate the matter, and strengthen the telco’s infrastructure and processes, and said they have advised other telcos in Singapore to step up their defences in case there are similar disruptions to their systems.
Members of the public are also advised to adopt “good cyber hygiene practices” to secure their devices. SingCERT will publish an advisory on what businesses and individuals should do to ensure their Internet-connected devices are secure, CSA and IMDA said.
BUSINESSES SHOULD MAKE CYBER SECURITY A PRIORITY: YAACOB
Communications and Information Minister Yaacob Ibrahim called on businesses to take action to address their specific cyber security needs, even as the Government steps up efforts to help them stay safe.
Speaking at an Asia Pacific cyber security summit on Wednesday, Dr Yaacob said the Government has been consistent in pursuing cyber security development, working with multiple stakeholders, including businesses and international partners. This includes launching the national cyber security strategy earlier this month, and developing a multi-tiered cyber security response plan.
A new Cybersecurity Act is also in the pipeline.
But Dr Yaacob emphasised that the Government cannot do it alone, and urged companies to make cyber security a priority.
"Cyber security should not be seen as a cost, but as an investment to manage risk. Under-investment in cyber security does not mean 'business-as-usual'. Weak cyber defences suffering from under-investment could be breached more easily, leading to disruption of business activities and significant losses," the minister said.
- CNA/dl
- wong chee tat :)
Posted 26 Oct 2016 21:20 Updated 26 Oct 2016 23:35
SINGAPORE: The Distributed Denial of Service (DDoS) attacks on StarHub’s broadband network were the first of that nature on Singapore's telco infrastructure, the Cyber Security Agency of Singapore (CSA) and Infocomm Media Development Authority (IMDA) said on Wednesday evening (Oct 26).
This comes after the telco revealed in a media briefing on Wednesday that compromised devices such as webcams and routers owned by its customers led to the DDoS attacks.
In a joint statement, CSA and IMDA said attacks on Domain Name Services (DNS), as seen in StarHub’s case, are “generally rare”, “although the latest Dyn incident in US has shown that it is surfacing as an emerging trend”.
The agencies added that in DDoS attacks, attackers usually scan for vulnerable Internet-connected devices commonly known as "botnet" and employ a list of techniques - such as password cracking - to gain access to them.
“Any Internet-connected device, from WiFi routers to printers to CCTVs, can inadvertently be part of a network of ‘bots’ that can be activated to attack other systems,” CSA and IMDA said, adding that there is no foolproof solution as digital systems are increasingly connected.
As such, telcos must ensure they have “resilient and robust” systems, and put in place measures to quickly detect and respond to such attacks, so as to avoid disruption of services to their subscribers, CSA and IMDA added.
They reiterated that they are working “closely” with StarHub to investigate the matter, and strengthen the telco’s infrastructure and processes, and said they have advised other telcos in Singapore to step up their defences in case there are similar disruptions to their systems.
Members of the public are also advised to adopt “good cyber hygiene practices” to secure their devices. SingCERT will publish an advisory on what businesses and individuals should do to ensure their Internet-connected devices are secure, CSA and IMDA said.
BUSINESSES SHOULD MAKE CYBER SECURITY A PRIORITY: YAACOB
Communications and Information Minister Yaacob Ibrahim called on businesses to take action to address their specific cyber security needs, even as the Government steps up efforts to help them stay safe.
Speaking at an Asia Pacific cyber security summit on Wednesday, Dr Yaacob said the Government has been consistent in pursuing cyber security development, working with multiple stakeholders, including businesses and international partners. This includes launching the national cyber security strategy earlier this month, and developing a multi-tiered cyber security response plan.
A new Cybersecurity Act is also in the pipeline.
But Dr Yaacob emphasised that the Government cannot do it alone, and urged companies to make cyber security a priority.
"Cyber security should not be seen as a cost, but as an investment to manage risk. Under-investment in cyber security does not mean 'business-as-usual'. Weak cyber defences suffering from under-investment could be breached more easily, leading to disruption of business activities and significant losses," the minister said.
- CNA/dl
- wong chee tat :)
Labels:
2016,
computer network,
computer networking,
cyber security,
cyberrange,
cyberspace,
ddos,
dns,
dos,
dyn,
Google Public DNS service,
market,
mobile network,
network,
oct,
opportunities,
outages,
router,
StarHub
Subscribe to:
Posts (Atom)