DDoS is going offline

A couple of years ago, research agencies and information security service providers began reporting on a decrease in the number of DDoS attacks. However, by the first quarter of 2019, the same researchers reported an astonishing increase of 84%. Since then, the trend has only escalated. Even the pandemic did not contribute to an atmosphere of peace—on the contrary, cybercriminals and spammers saw it as a perfect signal to attack, and the volume of DDoS attacks doubled twofold.

DDoS is going offline

We are confident that the era of simple and easily detectable DDoS attacks (and straightforward tools to prevent them) is over. Cybercriminals have learned to better hide these attacks and conduct them in increasingly sophisticated ways. The dark industry has shifted from brute force attacks to application-level attacks. It receives serious orders to disrupt business processes, including quite offline operations.

Infiltrating reality

In 2017, a series of DDoS attacks targeted Sweden's transport services, resulting in prolonged train delays. In 2019, the national railway operator of Denmark, Danske Statsbaner had its sales systems shut down. As a result, ticket vending machines and automatic gates at stations were inoperable, and over 15,000 passengers were unable to travel. In the same year, a powerful cyberattack caused a blackout in Venezuela.

The consequences of DDoS attacks are now felt not only by online users but also by people, as they say, IRL (in real life). Although historically attackers targeted only online services, now their goal is often to disrupt any business operations. Our estimates indicate that today over 60% of attacks have this purpose—either for extortion or unscrupulous competitive practices. Transactions and logistics are particularly vulnerable in this regard.

Smarter and more expensive

DDoS continues to be considered one of the most common and rapidly growing types of cybercrime. Experts predict that the number of such attacks will only increase from 2020 onwards. This is attributed to various reasons—ranging from the further shift of businesses online due to the pandemic, the evolution of the shadowy cybercrime industry itself, and even the spread of 5G.

DDoS attacks became popular due to their ease of deployment and low cost: just a couple of years ago, they could be initiated for $50 a day. Today, both the targets and the methods of attack have evolved, leading to increased complexity and consequently, cost. While prices starting from $5 an hour still exist on the price lists (yes, cybercriminals do have price lists and tariffs), the cost for a site with protection now demands at least $400 per day, and the price for 'custom' orders for large companies can reach several thousand dollars.

There are currently two main types of DDoS attacks. The first type aims to make an online resource unavailable for a certain period of time. The payment for these attacks is based on the duration of the attack itself. In this case, the DDoS operator doesn't care about any specific outcome, and the client essentially makes a prepayment for the start of the attack. These methods are relatively cheap.

The second type consists of attacks that are charged only upon achieving a specific result. These are much more interesting. They are significantly more complex to execute, and therefore much more expensive, as attackers must choose the most effective methods to achieve their goals. At Variti, we sometimes engage in full chess matches with cybercriminals, who instantly change tactics and tools, attempting to break through multiple vulnerabilities at various levels all at once. These are clearly coordinated attacks, where hackers know how to react and counter the defenders' actions. Fighting them is not only challenging but also very costly for companies. For instance, one of our clients, a large retail chain, kept a team of 30 people for nearly three years whose sole task was to combat DDoS attacks.

According to Variti, simple DDoS attacks, carried out solely out of boredom, trolling, or dissatisfaction with a specific company, currently account for less than 10% of all DDoS attacks (of course, unsecured resources may have different statistics; we are looking at our clients' data). The rest is the work of professional teams. Moreover, three-quarters of all 'bad' bots are sophisticated bots that are difficult to detect with most modern market solutions. They mimic the behavior of real users or browsers and implement patterns that complicate the distinction between 'good' and 'bad' requests. This makes the attacks less noticeable and, consequently, more effective.

DDoS is going offline
Data from GlobalDots

New DDoS Targets

Report Bad Bot Report from analysts at GlobalDots indicates that bots currently generate 50% of all web traffic, with 17.5% of them being malicious bots.

Bots can disrupt companies in various ways: in addition to 'taking down' websites, they now also increase advertising costs, click on ads, scrape prices to make them slightly lower and lure customers away, and steal content for various malicious purposes (for example, we recently reported discussed sites with stolen content that force users to solve someone else's CAPTCHAs). Bots significantly distort various business statistics, which leads to decisions being made based on incorrect data. A DDoS attack is often a smokescreen for even more serious crimes like hacking and data theft. And now we see that an entirely new class of cyber threats has emerged — the disruption of specific business processes within a company, often offline (since nowadays, nothing can be completely 'off the network'). We particularly often see disruptions in logistics processes and communications with clients.

Undelivered

Logistics business processes are critical for most companies, making them frequent targets of attacks. Here are the potential attack scenarios.

Out of stock

If you work in e-commerce, you’re probably already familiar with the problem of fake orders. In such attacks, bots overload logistical resources and make products unavailable to other buyers. They place a huge number of fake orders equal to the maximum number of items in stock. These items are later unpaid and returned to the site after some time. But the damage is done: they were marked as 'out of stock,' and some buyers have already turned to competitors. This tactic is well-known in the airline industry, where bots sometimes instantly 'buy up' all tickets as soon as they become available. For example, one of our clients—a large airline—suffered from such an attack orchestrated by Chinese competitors. In just two hours, their bots ordered 100% of the tickets on certain routes.

Sneakers bots

The next popular scenario: bots instantly purchase the entire product line, and their owners sell them later at inflated prices (the average markup is 200%). These bots are called sneakers bots, as this problem is well-known in the sneaker industry, especially with limited collections. Bots quickly snapped up newly released lines within minutes, effectively blocking the site so that real users couldn't get through. This is a rare case where bots have been written about in fashion magazines. Although, in general, ticket resellers for high-demand events like football matches use the same scenario.

Other scenarios

But that’s not all. There’s an even more complex version of logistic attacks that poses serious losses. This can happen if the service offers a 'Cash on Delivery' option. Bots leave false orders for such products, providing fake or even real addresses of unsuspecting individuals. Companies incur massive costs for delivery, storage, and investigation of details. Meanwhile, the products are unavailable for other customers and take up space in the warehouse.

What else? Bots leave mass fake negative reviews about products, clog up the refund function, block transactions, steal customer data, and spam real buyers — the options are countless. A good example is the recent attack on DHL, Hermes, AldiTalk, Freenet, Snipes.com. Hackers pretended, that they were 'testing DDoS protection systems', but ultimately took down the company’s business client portal and all APIs. As a result, there were significant delivery disruptions for customers.

Call tomorrow

Last year, the Federal Trade Commission (FTC) reported a doubling of complaints from businesses and users about spam and fraudulent robocalls. According to some estimates, they account for almost 50% of all calls.

As with cases of DDoS, the targets of TDoS — mass bot attacks on phones — vary from 'pranks' to unscrupulous competitive practices. Bots can overload contact centers and prevent real customers from getting through. This method is effective not only for call centers with 'live' operators but also in systems that use AVR. Bots can also launch massive attacks on other customer communication channels (chats, emails), disrupt CRM systems, and even adversely affect personnel management to some extent, as operators are overwhelmed trying to cope with the crisis. Attacks can also be synchronized with traditional DDoS attacks on the victim's online resources.

Recently, a similar attack disrupted emergency services 911 in the U.S. — ordinary people in urgent need of help simply could not get through. At about the same time, Dublin Zoo faced the same fate: at least 5,000 people received spam in the form of text SMS messages urging them to urgently call the zoo's phone number and ask for a fictional person.

Wi-Fi will not be available

Cybercriminals can easily block an entire corporate network. IP blocking is often used as a countermeasure against DDoS attacks. However, this approach is not only ineffective but also highly dangerous. An IP address can be easily identified (for example, through resource monitoring) and easily replaced (or spoofed). Our clients have had instances before joining Variti where blocking a specific IP simply disabled Wi-Fi in their own offices. There was a case where a client was 'tricked' into accepting the wrong IP, which blocked access to their resource for users from an entire region, and they didn't notice for a long time because the resource was functioning perfectly otherwise.

What’s New?

New threats require new protection solutions. However, this new niche in the market is just beginning to take shape. There are numerous solutions for effectively countering simple bot attacks, but the complex ones are more challenging. Many solutions still practice IP blocking methods. Others need time to gather initial data before starting operations, and those 10-15 minutes can be a vulnerability. There are machine learning-based solutions that can identify bots by their behavior. At the same time, the teams on 'the other side' boast that they already have bots that can mimic real, indistinguishable human patterns. It's unclear who will outsmart whom.

What to do when faced with professional bot teams and complex, multi-stage attacks at multiple levels?

Our experience shows that it's crucial to focus on filtering illegitimate requests without blocking IP addresses. For complex DDoS attacks, filtering needs to occur at multiple levels, including transport layer, application layer, and API interfaces. This approach can mitigate even low-frequency attacks, which are usually unnoticed and often passed through. Finally, it is essential to allow all legitimate users even during the active phase of an attack.

Secondly, companies need the capability to create their own multi-layered protection systems, where, in addition to DDoS attack prevention tools, systems for fraud detection, data theft prevention, content protection, and so on, are integrated.

Thirdly, they must operate in real-time from the very first request — the ability to respond instantly to security incidents significantly increases the chances of preventing an attack or mitigating its destructive impact.

The near future: reputation management and big data collection using bots
The history of DDoS has evolved from simple to complex. Initially, attackers aimed to take down websites. Now, they find it more effective to target core business processes.

The complexity of attacks will continue to grow; it's inevitable. In addition to what bad bots are currently doing — data theft and falsification, extortion, spam — bots will increasingly gather data from numerous sources (Big Data) and create 'trustworthy' fake accounts to manage influence, reputation, or for mass phishing.

Currently, only large companies can afford to invest in protection against DDoS and bots, but even they cannot always fully track and filter traffic generated by bots. The only positive aspect of increasingly complex bot attacks is that it drives the market to develop 'smart' and more advanced protection solutions.

What do you think — how will the bot protection industry evolve, and what solutions are needed in the market right now?

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster