0% found this document useful (0 votes)
31 views3 pages

Understanding Watering Hole Attacks

This document discusses waterhole attacks (WHA), which target organizations by infecting websites that are frequently visited by their employees. The document describes how WHAs work, including how attackers identify commonly accessed sites and inject malware onto those sites. It also discusses ways to detect and prevent WHAs, such as using updated antivirus software, securing DNS registrations, and correlating attacks with known advanced persistent threat activities. The challenges of WHAs include lack of visibility across multiple offices and sites moving to encrypted SSL connections. Overall, the document provides an overview of WHAs, including the key stages of such attacks and some potential defenses against them.

Uploaded by

Răzvan Ceuca
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
31 views3 pages

Understanding Watering Hole Attacks

This document discusses waterhole attacks (WHA), which target organizations by infecting websites that are frequently visited by their employees. The document describes how WHAs work, including how attackers identify commonly accessed sites and inject malware onto those sites. It also discusses ways to detect and prevent WHAs, such as using updated antivirus software, securing DNS registrations, and correlating attacks with known advanced persistent threat activities. The challenges of WHAs include lack of visibility across multiple offices and sites moving to encrypted SSL connections. Overall, the document provides an overview of WHAs, including the key stages of such attacks and some potential defenses against them.

Uploaded by

Răzvan Ceuca
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ISSN: 2347-971X (online) International Journal of Innovations in Scientific and

ISSN: 2347-9728(print) Engineering Research (IJISER)

A STUDY ON WHA (WATERING HOLE ATTACK) – THE MOST DANGEROUS


THREAT TO THE ORGANISATION

[Link]

P G Scholar, Department Of CSE, Sri Ramakrishna Engineering College, Coimbatore, India


krithikanatarajan22@[Link]

Abstract: This paper deals with the survey on the serious threat to the organization (i.e.) WHA (WATERINGHOLE
ATTACK). There are number of attacks in real world. Detecting and removing threat is one of the challenging tasks
to the individual as well as to the organization. The Criminals, hacks frequent visited sites and inject a malicious
code in to that specific sites. We describe how the WHA emerges, what are the root causes and necessary ways to
prevent them in future.

Keywords: WHA (watering hole attack), RTA (remote access Trojan), SQA (Sequential Mining Approach)
1. INTRODUCTION: system is running a vulnerable piece of software, an
Waterhole attack is one of the computer attacks. It exploit is delivered. The vulnerabilities found are
targets mainly on a particular group of organization, phoned to home back along with cookies.
industry and region. In this waterhole, the attacker
guesses which website the group repeatedly uses and 2. HOW WHA WORKS:
infects them with the malware. The indirect nature of Hackers target the organization by using hacking tools ,
this attack could be known by a desire that infect a where the employees use the sites frequently. [12] The
specific site of weak links. [2] The main aim of the attacker’s uses common internet tracking tools such as
hackers is to hack the particular group / company. The add this and kiss metrics to identify the sites that users
main idea in this waterhole attack is that hackers insert frequently visited. The figure depicts the working flow
any malicious code into the email / spam, employees or of WHA
users ignore them. So that avoid this hackers uses a new Inject code into the
technique called as waterhole attack where they insert a selected sites often
malware into frequently visited site to the company, visited by the users/
organization (Individual / group) PC. employees
The general survey is conducted on the recent
works related to the watering hole attack. [3] The
earliest survey of this year tells that the attackers target
on the energy sector where they infused light out
exploit kit (EK) into the website of thirty Nine Essex Attackers gathers Drops malware on
street LLP. After which if any browser connected to a initial step to to the vulnerable
malicious page on the site would be probed to establish determine which systems to gain
a finger print of client machine. After that Remote site to be targeted. access
Access Trojan (RAT) was installed, in order to hack the
complete detailed of the targeted machine.
The recent attack involves in US department of
Labor [17]. Cisco identifies the suspicious Get request
made to [Link]. A malicious or Using the drop
infected site which are recently linked with Department malware attackers
of labor attack. First, the victim visits one of the sites initiate its malware
activities
called [Link] [17]. This sites loads malicious
content and their purpose is to scan the victim machine
for Antivirus Software. After they collect data, the Figure 1: Working Principle Of WHA (Watering
victim machine phones home its configured data. If the Hole Attack)

[Link] 196 Vol 4 Issue 8 AUG 2017/101


ISSN: 2347-971X (online) International Journal of Innovations in Scientific and
ISSN: 2347-9728(print) Engineering Research (IJISER)

Hackers insert malware on to the specific sites and wait Standard malware defenses are one of the answers
for the user to visit. Once the user visited the site, for protecting against WHA [13]. Once the malware is
hackers identify the vulnerabilities by outdated in browser, it captures all the passwords and sensitive
antivirus & browser. [12] Using Drive by download information. To prevent these attacks, enterprise can
technique, the attackers don’t need user to click or remove / disable the targeted software which includes
download any files. A small code is downloaded JRE, Flash, Adobe Reader & IE from system at risk.
automatically in the background depends on the users [13] To keep attackers from redirections, Secure the
access rights, by this the attacker can gain the DNS registration and name servers.[13] Look for third
information such as information of the customer, party content and plan to disable them.[13] Use web
internet protocol address. After which exploit is application firewall with cross site scripting, command
delivered to the targeted machine. Attackers access the injection & SQL injection rules in deny mode.
targeted information by stealing the intellectual
property for gaining access to the information. Insert 4.1 Correlating well known Advanced Persistent
malware into the source code of the site that the user Threat (APT) activities:
visited, and steal data to commit fraud or sell the Organizations have to correlate and associate with wild
information to the criminals for gaining money. cybercrime so that we can get up to date news above the
hacking activity. And thus we can recovery / prevent
2.1 Tracking Services: from this type of attack.
Hackers identifying tracking service (i.e.) when users
without their knowledge provide all the information by 5. CHALLENGES:
simply surfing the internet. [12] By doing this Visibility is one of the significant challenges for
automated tracking methods used by marketing and ad enterprises [18]. It has always been an issue for
tracking services identify the traffic patterns. There enterprises with multiple offices and security resources
tracking service silently capture all the data’s without from different vendors. As many website moves to SSL
users knowledge. This shows that which sites by default in order to protect and user privacy. This
employees are accessing frequently and this allows the gains importance to the attackers where they hide their
information for the attackers to enter into the companies attacks from security solutions.
browsing and cloud services. If when a user visits the
site, the code that redirects the users browses to 6. CONCLUSION AND WAYS TO AVOID IN
malicious site, so that the user machine can be assessed FUTURE:
for vulnerabilities. Since the technology are developing rapidly a way to
protect our data also increases people should be aware
3. HOW TO DETECT THE WHA: of the attacks / threats and how to come out of it.
WHA can be detected by technique called as Sequential Follow the security measures and awareness to avoid
Mining Approach (SQA). SQA aims to find sequential with in future. By creating awareness enterprises wide
patterns in time-ordered data [19]. Its quality can be and regular threat testing technique tools like Data
measured by two factors called support and Breach Response Toolkit (DBRT) by Global Digital
confidence. Support is a pattern proportion of various Forencies (GDF) has one of the top priorities to avoid
sequences in which pattern occurs [19]. Confidence is with in future call 1-800-868-8169 for more
the ratio between the supports. For detecting WHA we information about DBRT.
need low support and high confidence patterns.
REFERENCES
4. WHA PREVENTION:
1. [Link]
For protecting against the WHA, use an updated version
2. [Link]
of antivirus. Use Google chrome or Firefox with add-
hole-attack
ons or extensions like security enhancers that would ask 3. [Link]
for the user permission before redirecting. Always /[Link]
check for the latest information security news sites for 4. [Link]
the latest threats. forbes-website-watering-hole-attack-security-firms

[Link] 197 Vol 4 Issue 8 AUG 2017/101


ISSN: 2347-971X (online) International Journal of Innovations in Scientific and
ISSN: 2347-9728(print) Engineering Research (IJISER)

5. [Link]
dfs/b istr_18_watering_hole_edits.[Link]
6. [Link]
becoming-increasingly-popular-says-
study/article/542694/
7. [Link]
present-largest-innovation-for-targeted-
attacks/article/543771/
8. [Link]
web-page-serves-watering-hole-attack/article/543538/
9. [Link]
zero-day-used-watering-hole-attacks-to-compromise-
users/article/542679/
10. [Link]
plants-malware-at-news-sites-to-spy-on-chinese-
dissidents/article/543726/
11. [Link]
h-out-for-waterhole-attacks----hackers--latest-stealth-
[Link]
12. [Link]
blog/watering-hole-attacks-protecting-yourself-from-the-
latest-craze-in-cyber-attacks/
13. [Link]
hole-attacks-an-increasingly-common-technique/
14. [Link]
against-watering-hole-attacks-Consider-using-a-secure-
VM
15. [Link]
[Link]
16. [Link]
encyclopedia/web attack/137/watering-hole-101
17. [Link]
attractive-alternative-to-spear-phishing
18. [Link]
/[Link]
19. [Link]
approach-for-watering-hole-attack-detection

[Link] 198 Vol 4 Issue 8 AUG 2017/101

You might also like