- More than 733 million unique IP addresses connected to the Akamai Intelligent Platform
- Identified surge in observed attack traffic originating from Indonesia
- Global average peak connection speed rose 36 percent year over year
Kuala Lumpur - July 24, 2013 – Akamai Technologies, Inc. (NASDAQ: AKAM), the leading cloud platform for helping enterprises provide secure, high-performing user experiences on any device, anywhere, today released its First Quarter, 2013 State of the Internet Report. Based on data gathered from the Akamai Intelligent Platform™, the report provides insight into key global statistics such as network connectivity and connection speeds, attack traffic, and broadband adoption and availability, among many others.
The First Quarter, 2013 State of the Internet Report includes new observations on “account checker” attacks targeting e-commerce sites and the impact on Akamai traffic from events including the death of Hugo Chavez, announcement of the new Pope, and undersea cable disruptions. The report also reviews mobile browser usage by network type based on data from Akamai IO.
Highlights from Akamai’s First Quarter, 2013 State of the Internet Report:
Global Internet Penetration
More than 733 million unique IPv4 addresses from 243 countries/regions connected to the Akamai Intelligent Platform, an increase of 3.1 percent over the previous quarter and 10 percent year over year. Since a single IP address can represent multiple individuals in some cases – such as when users access the Web through a firewall or proxy server – Akamai estimates the total number of unique Web users connecting to its platform during the quarter to be well over one billion.
Among the top 10 countries that connected to the Akamai Intelligent Platform in the first quarter, quarterly growth ranged from 0.7 percent in Germany to 5.3 percent in China. Across the full set of observed countries/regions worldwide, nearly 75 percent saw a quarterly increase in unique IP address counts.
Year-over-year, the number of global unique IP addresses connecting to Akamai grew by 10 percent – an increase of more than 73 million over the first quarter of 2012. Among the top 10 countries, yearly growth ranged from 1 percent in the United States to double-digit growth in the United Kingdom (11 percent), Russia (15 percent), Italy (20 percent), China (20 percent) and Brazil (38 percent). Worldwide, nearly 75 percent of countries/regions had higher unique IP address counts year-over-year.
Attack Traffic and Top Ports Attacked
Akamai maintains a distributed set of unadvertised agents deployed across the Internet that log connection attempts, which the company classifies as attack traffic. Based on the data collected by these agents, Akamai is able to identify the top countries from which attack traffic originates, as well as the top ports targeted by these attacks. It is important to note, however, that the originating country as identified by the source IP address may not represent the nation in which an attacker resides. For example, an individual in the United States may be launching attacks from compromised systems anywhere in the world.
Akamai observed attack traffic originating from 177 unique countries/regions during the first quarter of 2013, the same number that was observed in the fourth quarter of 2012. While China kept its position as the single-largest volume source of observed traffic with 34 percent of the total (down from 41 percent in the previous quarter), Indonesia took over second place with 21 percent of observed traffic (up from 0.7 percent in the previous quarter). The United States dropped from second to third with 8.3 percent of observed traffic (down from 10 percent in the previous quarter).
The top 10 countries/regions generated more than 80 percent of the observed attack traffic during the quarter. More than half of the total observed attack traffic originated from China and Indonesia.
Port 445 (Microsoft-DS) continued to be the most targeted port in the first quarter, receiving 23 percent of observed attack traffic. Port 80 (WWW HTTP) was second at 14 percent, with a majority of these attacks observed to be originating in Indonesia.
Observations on DDoS Attacks
Starting in the fourth quarter of 2012, the State of the Internet Report includes insight into DDoS attacks based on reports from Akamai customers. In the first quarter of 2013, Akamai customers reported 208 attacks, up slightly from the 200 reported in the previous quarter. Of those attacks, 35 percent targeted Enterprise customers; 32 percent were focused on Commerce customers; 22 percent on Media customers; 7 percent on High Tech customers; and 4 percent targeted Public Sector customers. Attacks were reported by 154 different organizations in the first quarter of 2013.
‘Account Checker’ Attacks
In the first quarter of 2013, Akamai observed attempted account takeover behavior for numerous e-commerce organizations that resulted from reuse of credentials obtained from other sites. Using automated tools known as “account checkers,” attackers can quickly determine valid user ID/password combinations across a large number of e-commerce sites. Once an account is breached, attackers can collect a user’s personal data and credit card information to use for further fraud.
Global Average and Peak Connection Speeds
Quarter-over-quarter, the global average connection speed rose 4 percent to 3.1 Mbps (up from 2.9 Mbps). A total of 117 countries/regions that qualified for inclusion saw average connection speeds increase this quarter, ranging from 0.7 percent in Kuwait to 75 percent in Guatemala.
Year-over-year, average connection speeds grew by 17 percent, with eight of the top 10 countries/regions growing by double-digit percentages. Around the world, 123 qualifying countries/regions saw a year-over-year increase in average connection speeds, ranging from 1.4 percent in Oman to 122 percent in Iraq.
Global average peak connection speeds increased 9.2 percent to 18.4 Mbps during the first quarter of 2013. Hong Kong was again number one at 63.6 Mbps, an increase of 9 percent over the previous quarter.
Year-over-year, global average peak connection speeds continued to show strong long-term growth, rising 36 percent. Global broadband (>4 Mbps) adoption increased 5.8 percent during the quarter to reach 46 percent. Global high broadband (>10 Mbps) reached 13 percent on a 10 percent increase over last quarter.
“This quarter’s State of the Internet Report shows continued positive growth in terms of Internet and broadband adoption worldwide. We have seen overall increases in average and peak connection speeds along with greater broadband penetration on both a quarterly and annual basis,” said David Belson, the report’s editor. “However, the levels of malicious activity we’ve observed show no signs of abating, as evidenced by the ongoing rise in DDoS attacks. This reinforces the continued need for vigilance by organizations that are conducting business and maintaining a presence on the Internet.”
Mobile Connectivity
In the first quarter of 2013, average connection speeds on surveyed mobile network operators ranged from a high of 8.6 Mbps to a low of 0.4 Mbps. Nine operators demonstrated average connection speeds in the broadband (>4 Mbps) range while 64 more operators showed average connection speeds above 1 Mbps. Data collected by Ericsson indicates that the volume of mobile data traffic doubled from the first quarter of 2012 to the first quarter of 2013, and grew 19 percent between the fourth quarter of 2012 and the first quarter of 2013.
An initial release of an updated data source for Akamai IO occurred in mid-February 2013, resulting in significant changes in observed device/browser adoption levels. For the first half of the quarter, mobile devices on cellular networks using the Android Webkit accounted for just over 41 percent of total requests, while Apple Mobile Safari accounted for 38 percent. In the second half of the quarter, Android Webkit was responsible for nearly 44 percent of requests and Apple Mobile Safari accounted for just over 30 percent. When measuring mobile devices across all network types, Apple Mobile Safari accounted for approximately 60% and Android Webkit was responsible for 20-33% of requests.
Akamai in 60 Seconds
Akamai has also released “Akamai in 60 Seconds,” an online visualization presenting a snapshot of the broad range of activity occurring on the Akamai Intelligent Platform. Available at www.akamai.com/60seconds, the dynamic graphic highlights peak values for metrics such as video streaming, page views, route optimization calculations and DNS lookups among many others, as measured across a 60-second time period.
About the Akamai State of the Internet Report
Each quarter, Akamai publishes a “State of the Internet” report. This report includes data gathered from across the Akamai Intelligent Platform about attack traffic, broadband adoption, mobile connectivity and other relevant topics concerning the Internet and its usage, as well as trends seen in this data over time. To learn more and to access the archive of past reports, please visit www.akamai.com/stateoftheinternet. To download the figures from the First Quarter, 2013 State of the Internet Report, please visit http://wwwns.akamai.com/soti/soti_q113_figures.zip.
Wednesday, July 24, 2013
Akamai Releases First Quarter 2013 ‘State of the Internet’ Report
发表者
SC Cyberworld
0
评论
标签: Akamai Technologies, Android, Apple, DDoS
Monday, June 24, 2013
Barracuda Firewall Integrates with Client ‘Fingerprinting’ to protect against DDoS attacks
Barracuda Web Application Firewall, version 7.8 firmware, increases protection for businesses against Distributed Denial of Service (DDoS) Attacks
KUALA LUMPUR, Malaysia, 18 June 2013 – Barracuda Networks Inc., a leading provider of security, networking and data protection solutions, today announced the latest Barracuda Web Application Firewall (WAF), version 7.8 firmware, specifically aimed at reducing the impact of automated attack attempts from botnets.
Thiban Darmalingam, the Regional Manager for Barracuda in Malaysia said “Automated botnet attacks have made headlines by striking high profile banks and web platforms like WordPress. More worrying is the dramatic increase in the ferocity and duration of these attacks.”
“WAF has the ability to control traffic based on geographic regions, IP addresses, and client types – allowing administrators to fight botnets effectively. It has new features such as client fingerprinting techniques that can distinguish botnets from real human users, so as to block malicious requests from botnets,” he adds.
“Securing applications against automated attacks can be tedious if done manually. With the Barracuda WAF, you protect your network from the latest hacker attacks, without adding configuration changes or upgrades to your network,” ends Thiban.
With functions that optimize application delivery and availability, Barracuda Web Application Firewall is essential for all secure and effective web-application delivery. Some new capabilities designed to secure applications against advanced DDoS attacks include:
• Enhanced Botnet Identification with Barracuda IP Reputation – Enhanced Barracuda IP reputation security provides the WAF with extensive data on infected devices spanning all major security vectors including network, web, and email traffic; enables administrators to identify and thwart botnets attempting any DDoS attacks.
• Client Fingerprinting – Using techniques such as injecting JavaScript challenges in website responses, Barracuda Web Application Firewall can distinguish botnets from human users and block malicious requests from botnets.
• Automated CAPTCHA Challenges – Barracuda Web Application Firewall can automatically insert CAPTCHA challenges to suspicious clients without requiring any changes to the application.
• New Client Browser Control – New client browser control allows the WAF to set client browser behavior to reduce the risk of malicious javascripts, drive-by-downloads, and other browser-based attacks.
In addition to these advanced security capabilities, a number of management and performance enhancements have been added to the firmware release, including:
• Increased throughput up to 4Gbps on Barracuda Web Application Firewall models 960 and higher on the current hardware platform
• Integration with the Kerberos security protocol for single sign-on across disparate backend Web services
• Support for Certificate Revocation Lists (CRLs) for enhanced SSL certificate management.
Availability and Pricing:
Barracuda Web Application Firewall version 7.8 is available immediately at no additional charge to existing customers on the current hardware platform with an active Energize Update subscription or with an active virtual appliance license. Barracuda Web Application Firewall pricing in North America ranges from US$4,999 to US$61,599 depending on model, with no per user fees. For more information, please visit www.barracuda.com/waf.
发表者
SC Cyberworld
0
评论
标签: Barracuda Networks, DDoS, Security
Tuesday, March 5, 2013
Staying Clear of DDoS Attacks Amidst Turbulent Cyberspace
A multi-layer defence strategy, DNS server protection and IT infrastructure visibility will spare government agencies and businesses the pain and costs of denial of service attacks in Malaysia
MALAYSIA, 5 March 2013 - Starting out as simple denial of service assaults launched from a single computer, DDoS attacks have evolved − with the proliferation of botnets − into one of the biggest threats on the security landscape. Verizon in its 2012 Data Breach Investigations Report called these attacks “more frightening than other threats, whether real or imagined.”
Research firm Stratecast in a recent study also found that DDoS attacks are increasing by 20 percent to 45 percent annually, with application-based DDoS attacks in particular growing by triple digits. Stratecast added that attacking via DDoS is one of the most prominent tools used by the hacker community, oftentimes as part of a multi-technique attack strategy.
According to several local newspaper reports, cyber-attacks recently erupted between Malaysian and Filipino hackers over the intrusion and standoff between militants from Philippines and Malaysian Police force in Lahad Datu, Sabah.
Hackers claiming to be from Malaysian and Filipino chapters of the hacktivist group Anonymous attacked websites of both countries. Some claimed to have crashed a few Government websites, and publicly announced their exploits over Facebook.
“The evolution of DDoS attacks highlights the urgency with which governments and businesses must adopt a security strategy to defend themselves. There are proactive steps organizations can take to bolster defenses and reduce the risk of attack,” said Dato’ Seri George Chang, Fortinet’s regional vice president for Hong Kong and Southeast Asia.
Eric Chan - Fortinet's Solution Consulting Director for Southeast Asia & Hong Kong.
He pointed out that a DDoS strategy should attempt to maintain services − especially critical services − with minimum disruption. To that end, businesses can start by assessing the network environment and devising a response plan. Among other things, the plan should include backup and recovery efforts, additional surveillance, and ways to restore service as quickly and efficiently as possible.
“DDoS attacks − like other security threats − will only continue to grow and become more rampant in future. Researchers have found that DDoS attacks are growing not just in terms of frequency, but in terms of bandwidth and duration as well. A decade ago, for instance, 50 Gbps attacks were seen a couple of times a year. Now, such attacks can happen nearly every week. The evolving nature of DDoS technologies will require firms to make a paradigm shift that entails greater foresight and more proactive defences,” said Eric Chan, solution consulting director who is based at Fortinet’s Fortiguard Centre here in Kuala Lumpur.
For proactive protection, Fortinet Inc advises three key steps to follow: implementation of a multi-layer defence strategy, protection of DNS servers and other critical infrastructure, and lastly maintenance of visibility and control of the IT infrastructure.
1. Multi-Layer Defence
A multi-layer strategy is crucial in DDoS protection and this would involve dedicated on-premise solutions designed to defend and mitigate threats from all angles of the network. These tools should provide anti-spoofing, host authentication techniques, packet level and application-specific thresholds, state and protocol verification, baseline enforcement, idle discovery, blacklists/whitelists and geolocation-based access control lists.
When considering dedicated DDoS solutions, organizations need to make sure those will allow them not only to detect application-layer DDoS attacks and efficiently block common, generic or custom DDoS attack techniques and patterns but they will have the ability to “learn” to recognize both acceptable and anomalous traffic behavior patterns based on traffic flow. This traffic profiling is key as it helps detect and restrict threats faster while reducing the event of false positives.
For greater operational efficiency, firms should also look at DDos solutions that offer advanced virtualization and geo-location features.
With virtualization, policy administrators can establish and oversee multiple independent policy domains within a single appliance, preventing attacks delivered in one network segment from impacting other network segments.
Geolocation technologies, on the other hand, let firms block malicious traffic coming from unknown or suspicious foreign sources. This reduces load and energy consumption on the backend servers by eliminating traffic from regions outside the organization’s geographic footprint and market.
2. Safeguarding DNS Servers
As part of an overall defensive strategy, organizations must protect their critical assets and infrastructure. Many firms maintain their own DNS servers for Web availability, which are often the first systems to be targeted during a DDoS attack. Once DNS servers are hit, attackers can easily take down an organization’s Web operations, creating a denial of service situation. DNS protection solutions available on the market today can protect against transaction ID, UDP source port and case randomization mechanism intrusions.
3. Maintaining Infrastructure Visibility and Control
Organizations need a way to maintain vigilance and monitor their systems before, during and after an attack. It’s no secret that having a holistic picture into the IT environment allows administrators to detect aberrations in network traffic and detect attacks quickly, while giving them the intelligence and analytical capabilities to implement appropriate mitigation and prevention techniques. The best defences will incorporate continuous and automated monitoring, with alert systems that sound alarm bells and trigger the response plan should DDoS traffic be detected.
It’s important to have granular visibility and control across the network. This visibility into network behavior helps administrators get to the root of the attack’s cause and block flood traffic while allowing legitimate traffic to pass freely. It also hands administrators the ability to conduct real-time and historic attack analysis for in-depth forensics. In addition, advanced source tracking features can help defensive efforts by pinpointing the address of a non-spoofed attack, and can even contact the offender’s domain administrator.
Turning Attention Back to the Business
Organizations in Malaysia are urged by Fortinet to beef up their response plans and assess their network infrastructure vis-à-vis DDoS threats today. This should include shoring up defenses for critical servers and prioritizing data, implement management and monitoring capabilities to give them a comprehensive understanding of their whole network. Finally, IT administrators should be ready to implement fail-safe measures that quickly identify the source of the threat, minimize the impact of the attack, and restore service as soon as possible.


