Showing posts with label Los Angeles. Show all posts
Showing posts with label Los Angeles. Show all posts

Tuesday, November 1, 2016

DDoS defenses emerging from Homeland Security



By Evan Koblentz | October 31, 2016, 9:53 AM PST

Public, private, and academic researchers are working on new ways to combat distributed denial-of-service attacks. The recent large-scale attacks are making them even more determined.


Government, academic, and private-sector officials are collaborating on new ways to prevent and mitigate distributed denial-of-service (DDoS) attacks, based on research years in the making but kicked into high gear by the massive takedown this month of domain name system provider Dyn.


The largest attacks in summer 2015 were about 400 gigabits per second, but September 2016 saw an attack on security blogger Brian Krebs of more than 600Gbps, while Dyn said its own attack may have exceeded 1.2 terabits per second. Government-led research is focusing on the 1-terabit range but with systems that can scale higher, which is already needed due to the proliferation of vulnerable Internet of Things devices too easily commandeered by malicious hackers.



But it means there's a ton of job security for Dan Massey, a computer science Ph.D. serving as program manager for the U.S. Department of Homeland Security Advanced Research Projects Agency Cyber Security Division. Massey in August 2015 began evaluating and funding new anti-DDoS efforts at the National Institute of Standards and Technology (NIST), private companies, and universities, which share the goal of getting innovative techniques into commercially feasible pilot projects no later than summer 2018. Some are already underway, Massey and others said.


Funded projects include attack information sharing methods from the University of Southern California, University of California-Los Angeles, and University of Oregon; the latter implements a unique peer-to-peer method of letting networks share information about traffic patterns. Colorado State University is making a way to distribute the task of packet filtering and intelligence gathering; the University of Delaware and others including IBM are focusing on identifying new kinds of attacks; and the University of Houston is looking at on-demand network capacity for handling attacks when they hit. In addition, Waterford, Va.-based Waverley Labs and the Cloud Security Allianceare working on whitelisting methods to make a network only accept approved traffic. NIST is collaborating with the University of California-San Diego to determine whether the software for stopping DDoS attacks would hurt network performance.

Other anti-DDoS measures are already common for large companies, such as load balancing so that different parts of a network can pick up the slack if others go down, having multiple DNS providers for the same reason, and educating end users on safe internet usage, security experts at Akamai, Radware, and certification specialist (ISC)2 said. It's unclear why the
Related Posts Plugin for WordPress, Blogger...