Showing posts with label dyn. Show all posts
Showing posts with label dyn. Show all posts

Thursday, October 27, 2016

Broadband service outages due to DDoS attacks: StarHub

Broadband service outages due to DDoS attacks: StarHub
Posted 25 Oct 2016 15:36 Updated 25 Oct 2016 23:07

SINGAPORE: The two recent broadband service outages that hit StarHub were the result of "intentional and likely malicious attacks" on its servers, the telco confirmed on Tuesday (Oct 25), adding that the attacks were "unprecedented in scale, nature and complexity".

In a media statement, StarHub said: "We have completed inspecting and analysing network logs from the home broadband incidents on Oct 22 and Oct 24 and we are now able to confirm that we had experienced intentional and likely malicious distributed denial-of-service (DDoS) attacks on our domain name servers (DNS).

"These two recent attacks that we experienced were unprecedented in scale, nature and complexity," it said.

Starhub said that the DDoS attacks caused temporary web connection issue for some of its home broadband customers. "On both occasions, we mitigated the attacks by filtering unwanted traffic and increasing our DNS capacity, and restored service within two hours. No impact was observed on the rest of our services, and the security of our customers’ information was not compromised."

The broadband service provider said it would continue to stay vigilant against possible follow-up DDoS attempts, and is working closely with the authorities to determine intent and source of these two DDoS attacks.

Earlier on Tuesday, the Cyber Security Agency (CSA) and the Infocomm Media Development Authority (IMDA) said that the possibility of a DDoS attack could not be ruled out, and noted that StarHub's outages came on the heels of Friday’s attack against the US-based domain name system service provider Dyn.

StarHub had earlier said it detected a "spike in data traffic" coming into its domain name servers (DNS) that temporarily affected the Web connection for some of its home broadband customers during the time of the outage.

A DNS is a database that translates Web addresses, such as www.nameofwebsite.com, into machine readable sets of digits for customers to view websites on their computers.

"When a DNS is not operating optimally, customers may face difficulty in accessing the Internet," the telco said.

After detecting the sudden increase in traffic to the servers, StarHub said it immediately started filtering the unwanted traffic and added DNS capacity to manage the "huge increase in traffic load". As a result, some customers temporarily faced intermittent broadband access, it said.

The telco added that there was no impact on its mobile broadband, enterprise and home voice services, and the security of customers’ information was not compromised.

According to StarHub, the home broadband service for affected customers was fully restored at about 11.25pm on Monday.

The company said that initial investigations pointed to similarities between the outage on Monday and the first incident last Saturday.

- CNA/mz/ek

- wong chee tat :)

Compromised home devices triggered broadband outages: StarHub

Compromised home devices triggered broadband outages: StarHub
By Kevin Kwang  Posted 26 Oct 2016 19:10 Updated 27 Oct 2016 08:56

SINGAPORE: Web-connected devices bought by StarHub subscribers were the cause of the "illegitimate traffic" that resulted in the distributed denial of service (DDoS) the telco suffered twice in two days, said StarHub's chief technology officer (CTO) Mock Pak Lum on Wednesday (Oct 26).

In a media briefing, Mr Mock said affected devices such as broadband routers and webcams were responsible for the spike in Web traffic the telco saw last Saturday and Monday nights.

However, he did not disclose how many devices or IP addresses were compromised, or what was the exact volume in the spike in Web traffic its domain name server (DNS) farms had to handle in a short space of time.

The illegitimate traffic to the DNS resulted in an overload that disrupted Web connection for "some" broadband users, Mr Mock said. "Not everyone was affected," he added, saying that some users would have gotten to their desired webpage if they had waited long enough.

As remedial action, the telco said it has increased DNS capacity by 400 per cent since Saturday, and is also implementing traffic filtering and source tracing to identify the source of Web traffic surges.

It is also looking to deploy its technical team - HubTroopers - to subscribers identified with compromised devices to help them troubleshoot. This could either be done at their homes or, with their permission, taken back to StarHub for further investigation.

That said, the CTO said his team is working to scrub through the logs to see if the traffic spike was linked to the attack on US-based Dyn DNS. He noted that there are similarities in that compromised connected home devices were used to conduct the attack, but that it was too early to draw any conclusion.

He also could not comment as to why only StarHub was attacked by the compromised devices, while other Internet service providers were not affected.

StarHub is working with the Cyber Security Agency of Singapore (CSA) in terms of sharing information from its investigations, he added.

In the meantime, Mr Mock stressed that "everyone has a role to play in cybersecurity". "The reward is now too huge" for cybercriminals and the online threat will be "prevalent for a long time to come", the CTO said.

He suggested that consumers only get devices that are "reputable", remember to change the default passwords and set up the necessary defences such as firewalls after buying the devices.

He also cautioned against blindly opening up Web links sent from friends via emails, for instance, as this could potentially lead to malware being downloaded into the device without the user's knowledge.

DDoS ATTACKS LIKELY TO BE MORE COMMON: EXPERTS

The CSA and the Infocomm Media Development Authority (IMDA) said in a joint statement that the DDoS attacks are the first such incident against Singapore's telco infrastructure, and reiterated that they are working "closely" with StarHub to investigate the matter.

Commenting on StarHub's announcement, Mr John Lim, course manager at Nanyang Polytechnic's School of Information Technology, told Channel NewsAsia that he was not surprised that compromised embedded devices were used to stage the DDoS attacks.

He said that PCs and Macs have become much more secure today, but this is not so for devices such as webcams or routers.

"You cannot just install antivirus on these devices," Mr Lim said.

Additionally, consumers can now shop for such connected devices from e-commerce sites such as Taobao, and many times these are brands that are not known here and there is little to no information on the kind of defences manufacturers have installed, he said.

With the proliferation of these Web-connected devices, Mr Lim said he "won't be surprised if there will be other similar attacks that might affect the other two telcos" in the future.

Other experts Channel NewsAsia spoke to concurred, with one pointing to the gaining popularity of the Internet of Things.

"There's research done that 50 billion devices will be connected in 2020. Just imagine: 50 billion (devices) attacking your organisation," said Mr Vincent Loy, Asia Pacific Cyber & Financial Crime Leader at PwC Singapore.

Mr Loy too added that many devices are not built with security in mind.

"They were built to do a certain function; security was not part of it; they do not have password control. They do not have security control, they do not have a log in or back up. The Government and private sector need to work together to come up with a solution in coming up with security by design," Mr Loy said.

Mr Stephen Dane, a managing director at Cisco Systems (HK), pointed to the need for companies to pay more attention to security.

"It's really important to design a network and your infrastructure with high availability in mind, to ensure that not all your eggs are in one basket when it comes to protecting or providing data and holding records on behalf of customers; or in fact, having a website that's associated with just one domain name server," he said.

"It's important to build that resiliency into your infrastructure and ensure that there's high availability as much as possible, so that you are ensuring that the target is distributed as much as possible and therefore the risk is reduced," he added.

Additional reporting by Alice Chia.

- CNA/kk/dl

- wong chee tat :)

DDoS attack on StarHub first of its kind on Singapore's telco infrastructure: CSA, IMDA

DDoS attack on StarHub first of its kind on Singapore's telco infrastructure: CSA, IMDA
Posted 26 Oct 2016 21:20 Updated 26 Oct 2016 23:35

SINGAPORE: The Distributed Denial of Service (DDoS) attacks on StarHub’s broadband network were the first of that nature on Singapore's telco infrastructure, the Cyber Security Agency of Singapore (CSA) and Infocomm Media Development Authority (IMDA) said on Wednesday evening (Oct 26).

This comes after the telco revealed in a media briefing on Wednesday that compromised devices such as webcams and routers owned by its customers led to the DDoS attacks.

In a joint statement, CSA and IMDA said attacks on Domain Name Services (DNS), as seen in StarHub’s case, are “generally rare”, “although the latest Dyn incident in US has shown that it is surfacing as an emerging trend”.

The agencies added that in DDoS attacks, attackers usually scan for vulnerable Internet-connected devices commonly known as "botnet" and employ a list of techniques - such as password cracking - to gain access to them.

“Any Internet-connected device, from WiFi routers to printers to CCTVs, can inadvertently be part of a network of ‘bots’ that can be activated to attack other systems,” CSA and IMDA said, adding that there is no foolproof solution as digital systems are increasingly connected.

As such, telcos must ensure they have “resilient and robust” systems, and put in place measures to quickly detect and respond to such attacks, so as to avoid disruption of services to their subscribers, CSA and IMDA added.

They reiterated that they are working “closely” with StarHub to investigate the matter, and strengthen the telco’s infrastructure and processes, and said they have advised other telcos in Singapore to step up their defences in case there are similar disruptions to their systems.

Members of the public are also advised to adopt “good cyber hygiene practices” to secure their devices. SingCERT will publish an advisory on what businesses and individuals should do to ensure their Internet-connected devices are secure, CSA and IMDA said.

BUSINESSES SHOULD MAKE CYBER SECURITY A PRIORITY: YAACOB

Communications and Information Minister Yaacob Ibrahim called on businesses to take action to address their specific cyber security needs, even as the Government steps up efforts to help them stay safe.

Speaking at an Asia Pacific cyber security summit on Wednesday, Dr Yaacob said the Government has been consistent in pursuing cyber security development, working with multiple stakeholders, including businesses and international partners. This includes launching the national cyber security strategy earlier this month, and developing a multi-tiered cyber security response plan.

A new Cybersecurity Act is also in the pipeline.

But Dr Yaacob emphasised that the Government cannot do it alone, and urged companies to make cyber security a priority.

"Cyber security should not be seen as a cost, but as an investment to manage risk. Under-investment in cyber security does not mean 'business-as-usual'. Weak cyber defences suffering from under-investment could be breached more easily, leading to disruption of business activities and significant losses," the minister said.

- CNA/dl


- wong chee tat :)