Lawfare editor on persistent DDoS attack: 'We wish they'd knock it off'
Full article737 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The DDoS attack is a reminder of the prevalence of this blunt attack method and of a growing security market for defenses against it.
Influential national security blog Lawfare has been the target of a distributed denial-of-service attack since Wednesday, with attackers amplifying their efforts as security measures are used to stop the traffic barrage.
The DDoS attack knocked the site offline intermittently for a few hours on Wednesday, Executive Editor Susan Hennessey estimated, but the malicious traffic stubbornly persisted through Thursday.
The attack “increased substantially in response to preliminary defense measures,” Hennessey told CyberScoop in an email Thursday. The website appears to have stabilized, she said, despite the continuous pinging of Lawfare’s site.
“Previous attacks have taken us offline for longer periods, but we now have more sophisticated defenses in place so size doesn’t necessarily correlate to impact,” said Hennessey, a former attorney in the National Security Agency’s Office of General Counsel.
“While large, the attack hasn’t been especially sophisticated in morphing, so our current measures of just blocking the traffic seem to be working,” she added later on Thursday.
Lawfare is currently experiencing a distributed denial of service attack. We're aware of the issue and hope to be back online shortly.
— Lawfare (@lawfare) October 17, 2018
Hennessey said Lawfare, which publishes articles on national security law, uses a DDoS mitigation tool from San Francisco-based security company Cloudflare. Data from Cloudflare indicate that the primary attack originated in Seychelles and a secondary attack originated in Romania, according to Hennessey. As she pointed out, that does not mean the culprits are physically located in those countries; location-spoofing and hijacking computers in disparate locations are often tactics employed by those who launch DDoS attacks.
“While we have insight into the technical attack, we don’t know who is responsible or what their motivation might be,” Hennessey said, adding: “We wish they’d knock it off.”
While defenses have matured, DDoS attacks are still a cheap and popular tool of cyber criminals. The emergence in recent years of DDoS-for-hire services selling access to botnets has only accentuated this trend.
Andrew Shoemaker, founder of the testing company NimbusDDOS, said his customers “have reported an uptick in DDoS attacks in the last six months across a wide swath of industries.”
Shoemaker told CyberScoop that it is difficult to pin down the cause of that uptick, but offered one possible explanation. “It may simply be that a new tool exists in the black-hat community that is making it easier to form botnets and launch attacks,” he said.
More Scoops
Officials seize 53 DDoS-for-hire domains in ongoing crackdown
Operation PowerOFF’s latest globally coordinated action identified more than 75,000 alleged cybercriminals. Officials warned each of them to stop jamming up traffic.
Officials gain control of Rapper Bot DDoS botnet, charge lead developer and administrator
Six DDoS sites seized in multi-national law enforcement operation
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/lawfare-ddos-attack-cloudflare/