Keyloggers and Spywares
Keylogger
• Keyloggers or keystroke loggers are software programs or hardware
devices that track the activities (keys pressed) of a keyboard.
• Keyloggers are a form of spyware where users
are unaware their actions are being tracked.
• Keyloggers can be used for a variety of purposes.
• Hackers may use them to maliciously gain access to your private information
• Employers might use them to monitor employee activities.
• Somekeyloggers can also capture your screenat
random intervals; these are known as screen
recorders.
• Keylogger software typically stores your keystrokes in a small file, which is
either accessed later or automatically emailed to the person monitoring
your actions.
Keylogger
• Legitimate programs may have a keylogging function which can be used to
call certain program functions using “hotkeys,” or to toggle between
keyboard layouts.
• There is a lot of legitimate software which is designed to allow
administrators to track what employees do throughout the day, or to allow
users to track the activity of third parties on their computers.
• Ethical boundary between justified monitoring and espionage is a fine line.
• Legitimate software is often used deliberately to steal confidential user
information such as passwords.
• Most modern keyloggers are considered to be legitimate software or
hardware and are sold on the open market.
Keylogger
• Developers and vendors offer a long list of cases in which it would be legal
and appropriate to use keyloggers, including:
• Parental control: parents can track what their children do on the Internet,
and can opt to be notified if there are any attempts to access websites
containing adult or otherwise inappropriate content;
• Jealous spouses or partners can use a keylogger to track the actions of
their better half on the Internet if they suspect them of “virtual cheating”
• Company security: tracking the use of computers for non-work-related
purposes, or the use of workstations after hours
• Company security: using keyloggers to track the input of key words and
phrases associated with commercial information which could damage
the company (materially or otherwise) if disclosed;
• Other security (e.g. law enforcement): using keylogger records to
analyze and track incidents linked to the use of personal computers;
How Does a Keylogger Get on Your
Computer?
• Keylogger can be installed on your computer any number of ways.
• Anyone with access to your computer could install it.
• Keyloggers could come as a component part of
a virus or from any application installation, despite how deceptively
innocent it may look.
• This is part of the reason why you should always be sure you’re
downloading files from a trusted resource.
Why keyloggers are a threat
• Keyloggers present no threat to the system.
• They can pose a serious threat to users, as they can be used to intercept
passwords and other confidential information entered via the keyboard.
• Cyber criminals can get PIN codes and account numbers for e-payment
systems, passwords to online gaming accounts, email addresses, user
names, email passwords etc.
• Access to confidential data can sometimes have consequences which are
far more serious than an individual’s loss of a few dollars.
• Keyloggers can be used as tools in both industrial and political espionage,
accessing data which may include proprietary classified
government material which could commercial information and
compromise the security of commercial and state owned organizations ( for
example, by stealing priviate encryption keys)
Why keyloggers are a threat
• Keyloggers, phishing and social engineering are currently the main
methods being used in cyber fraud.
• Users who are aware of security issues can easily protect themselves
against phishing by ignoring phishing emails and by not entering any
personal information on suspicious websites.
• It is more difficult for users to combat keyloggers
• Only possible method is to use an appropriate security solution, as it’s
usually impossible for a user to tell that a keylogger has been installed on
his/ her machine.
• According to Cristine Hoepers, the manager of Brazil’s Computer
Emergency Response Team, which works under the aegis of the country’s
Internet Steering Committee, keyloggers have pushed phishing out of first
place as the most-used method in the theft of confidential information.
How cyber criminals use keyloggers
• In recent years, we have seen a considerable increase in the number of different kinds of malicious
programs which have keylogging functionality.
• No Internet user is immune to cyber criminals, no matter where in the world s/he is located and no
matter what organization s/he works for.
• One of the most publicized keylogging incidents recently was the theft of over $1million from client
accounts at the major Scandinavian bank Nordea.
• In August 2006 Nordea clients started to receive emails, allegedly from the bank, suggesting that
they install an antispam product, which was supposedly attached to the message.
• When a user opened the file and downloaded it to his/ her computer, the machine would be infected
with a well known Trojan called Haxdoor.
• This would be activated when the victim registered at Nordea’s online service, and the Trojan would
display an error notification with a request to re-enter the registration information.
• Keylogger incorporated in the Trojan would record data entered by the bank’s clients, and later
send this data to the cyber criminals’ server.
• This was how cyber criminals were able to access client accounts, and transfer money from them.
How cyber criminals use keyloggers
• According to Haxdoor’s author, the Trojan has also been used in attacks
against Australian banks and many others.
• On January 24, 2004 the notorious Mydoom worm caused a major
epidemic.
• MyDoom broke the record previously set by Sobig, provoking the largest
epidemic in Internet history to date.
• The worm used social engineering methods and organized a DoS attack on
[Link]; the site was either unreachable or unstable for several
months as a consequence.
• The worm left a Trojan on infected computers which was subsequently
used to infect the victim machines with new modifications of the worm.
• The fact that MyDoom had a keylogging function to harvest credit card
numbers was not widely publicized in the media.
How cyber criminals use keyloggers
• In early 2005 the London police prevented a serious attempt to steal
banking data.
• After attacking a banking system, the cyber criminals had planned to steal
$423 million from Sumitomo Mitsui’s London-based offices.
• The main component of the Trojan used, which was created by the 32-year-
old Yeron Bolondi, was a keylogger that allowed the criminals to track all
the keystrokes entered when victims used the bank’s client interface.
• In May 2005 in London the Israeli police arrested a married couple who
were charged with developing malicious programs that were used by some
Israeli companies in industrial espionage.
• The scale of the espionage was shocking: the companies named by the
Israeli authorities in investigative reports included cellular providers like
Cellcom and Pelephone, and satellite television provider YES.
How cyber criminals use keyloggers
• According to reports, the Trojan was used to access information relating to
the PR agency Rani Rahav, whose clients included Partner
Communications (Israel’s second leading cellular services provider) and
the HOT cable television group.
• The Mayer company, which imports Volvo and Honda cars to Israel, was
suspected of committing industrial espionage against Champion Motors,
which imports Audi and Volkswagen cars to the country.
• Ruth Brier-Haephrati, who sold the keylogging Trojan that her husband
Michael Haephrati created, was sentenced to four years in jail, and
Michael received a two-year sentence.
How cyber criminals use keyloggers
• In February 2006, the Brazilian police arrested 55 people involved in spreading malicious programs
which were used to steal user information and passwords to banking systems.
• The keyloggers were activated when the users visited their banks’ websites, and secretly tracked
and subsequently sent all data entered on these pages to cyber criminals.
• The total amount of money stolen from 200 client accounts at six of the country’s banks totaled
$4.7million.
• At approximately the same time, a similar criminal grouping made up of young (20 – 30 year old)
Russians and Ukrainians was arrested.
• In late 2004, the group began sending banking clients in France and a number of other countries
email messages that contained a malicious program – namely, a keylogger. Furthermore, these spy
programs were placed on specially created websites; users were lured to these sites using classic
social engineering methods.
• In the same way as in the cases described above, the program was activated when users visited
their banks’ websites, and the keylogger harvested all the information entered by the user and sent
it to the cyber criminals. In the course of eleven months over one million dollars was stolen.
• There are many more examples of cyber criminals using keyloggers – most financial cybercrime is
committed using keyloggers, since these programs are the most comprehensive and reliable tool for
Keylogger Software
• Remote - accesssoftware keyloggerscan allow accessto
locally recorded data from a remote location.
• This communication can happen by using one of followin
the methods: g
• Uploading the data to a website, database or FTP server.
• Periodically emailing data to a predefined email address.
• Wirelessly transmitting data through an attached hardware
system.
• Software enabling remote login to your local machine.
Keylogger Software
• Additional features that some software keyloggers come with can capture
additional information without requiring any keyboard key presses as input.
• They include:
• Clipboard logging – Anything that can be copied to the clipboard is captured.
• Screen logging – Randomly timed screenshots of your computer screen are logged.
• Control text capture – The Windows API allows for programs to request the text value
of some controls, meaning that your password may be captured even if behind a
password mask (the asterisks you see when you type your password into a form).
• Activity tracking – Recording of which folders, programs and windows are opened and
also
possibly screenshots of each.
• Recording of search engine queries, instant message conversations, FTP downloads
along with any other internet activities.
Keylogger Hardware
• Hardware-based keyloggers can monitor your activities without any software being
installed at all.
• Examples of these include:
• Keyboard hardware - These loggers take the form of a piece of hardware inserted
somewhere between the computer keyboard and the computer, typically along the
keyboard's cable connection. There are of course more advanced implementation
methods that would prevent any device from being visible externally. This type of
hardware keylogger is advantageous because it is not dependent on any software nor
can it be detected by any software.
• Wireless keyboard sniffers - It is possible for the signals sent from a wireless keyboard
to its receiver to be intercepted by a wireless sniffer.
• Keyboard overlays - Overlays are popular in ATM theft cases where thieves capture
a user's
PIN number.
• This device is designed to blend in with the machine so that people are unaware of its
presence.
Kernel/driver keyloggers
• This type of keylogger is at the kernel level and receives data directly from
the input device (typically, a keyboard).
• It replaces the core software for interpreting keystrokes.
• It can be programmed to be virtually undetectable by taking advantage of
the fact that it is executed on boot, before any user-level applications start.
• Since the program runs at the kernel level, one disadvantage to this
approach it that it fails to capture autocomplete passwords, as this
information is passed in the application layer.
How Can I Detect and Remove a Keylogger?
How Can I Detect and Remove a Keylogger?
• Begin by running your antivirus, which can often detect a keylogger
on your system.
• Run a program like Spybot Search and Destroy or MalwareBytes to
check for certain types.
• Check your task list by pressing ctrl+alt+del in Windows. Examine the
tasks running, and if you are unfamiliar with any of them, look them up
on a search engine.
• Scan your hard disk for the most recent files stored. Look at the contents
of any files that update often, as they might be logs.
• Use your system configuration utility to view which programs are loaded at
computer start-up. You can access this list by typing “msconfig” into the
run box.
Figure 1. File changes made by the Perfect Keylogger.
Figure 4. Ethereal captures the keylogger's outgoing email.
Anti-keylogging software
• To prevent keyloggers on the desktop level two types of anti-keylogging software is
available from
various vendors:
• Signature based anti-keylogger.
• These are applications that typically identify a keylogger based on the files or DLLs that it installs, and the
registry entries that it makes.
• Although it successfully identifies known keyloggers, it fails to identify a keylogger whose signature is not
stored in its
database.
• Some anti-spyware applications use this approach, with varying degrees of success.
• Hook based anti-keyloggers.
• A hook process in Windows uses the function SetWindowsHookEx(), the same function that hook based
keyloggers use.
• This is used to monitor the system for certain types of events, for instance a keypress/mouse-click --
however, hook based anti-keyloggers block this passing of control from one hook procedure to another.
• This results in the keylogging software generating no logs at all of the keystroke capture.
• Although hook based anti-keyloggers are better than signature based anti-keyloggers, note that they still are
incapable of stopping kernel-based keyloggers.
Spyware
[Link]
Spyware
• Although it sounds like something James Bond would employ, spyware is
all too real.
• Spyware is any software that installs itself on your computer and starts
covertly monitoring your online behavior without your knowledge or
permission.
• Spyware is a kind of malware that secretly gathers information about a
person or
organization and relays this data to other parties.
• In some cases, these may be advertisers or marketing data firms, which is
why spyware is sometimes referred to as “adware.”
• It is installed without user consent by methods such as a drive-by
download, a trojan included with a legitimate program or a deceptive pop-
up window.
Spyware
• Spyware uses your internet connection to relay personal information such
as your name, address, browsing habits, preferences, interests or
downloads.
• Other forms of spyware hijack your browser to point it to another website,
cause your device to place calls or send texts automatically, or serve
annoying ads even when you are offline.
• Spyware that steals your username, password or other credentials is
referred to as a “keylogger” – an insidious prerequisite for cyber crime.
• Signs of a spyware infection can include unwanted behaviors and
degradation of system performance. It can eat up CPU capacity, disk
usage and network traffic.
• Stability issues such as applications freezing, failure to boot, difficulty
connecting to the internet and system crashes are also common.
Spyware and User Privacy
• Not all data collection programs are spyware, as long as the user
fully understands what data is being collected and with whom it
is being shared.
• Tracking and reporting user information can help legitimate
software vendors to improve their products or better support
customers.
• For this reason, marketing firms often object to having their services
called "spyware."
• The line between illegal spyware and legitimate data collection is
often drawn at cookies, a well-known method of storing information
about internet behavior on individuals' devices.
• Some users allow cookies; others abhor them.
Spyware and User Privacy
• Divergent attitudes about the definitions of spyware make it an integral
concern of privacy experts, who question and debate its merit.
• Spyware is virtually unregulated.
• These programs seldom if ever include a mechanism for the user to
oversee and approve what information is being gathered and how it is
shared, even if the usage is lawful.
• Add to this the fact that spyware consumes computing resources like
bandwidth, processing power and memory without any control.
• It’s easy to see why security experts seek to prevent and defend against
spyware.
Spyware and User Privacy
Tips to Prevent Spyware
• Use an anti-spyware scanner. There are many anti-spyware programs available that will
scan your computer to detect malicious tracking software. Removing spyware from a
computer or device can be tricky, but it can always be quarantined to no longer function.
Most packages provide ongoing anti-spyware protection against the real-time installation
of new spyware by scanning incoming traffic and blocking any potential threats. Like any
anti-virus program, anti-spyware tools must be updated regularly to remain fully effective.
• Adjust browser security settings. Most browsers allow you to adjust their security levels
along a scale from “high” to “low.” Get to know these options, as some browsers can
function like a firewall against unwanted operations, even cookie installation if so desired.
• Be very wary of pop-ups. Ads and offers displayed in pop-up windows, especially those
that appear unexpectedly, often mask deceptive purposes. Some pretend a virus infection
has been discovered on your computer or offer a plug-in that purports to improve your
browsing experience. Never click "agree" or "OK" to close a window; instead click the red
"x" in the corner of the window to close. Practice skeptical computing – assume that any
new program is potentially harmful until proven safe. Answering “yes” to a prompt that you
don't understand can allow spyware to be loaded.
Tips to Prevent Spyware
• Understand that “free" is never “free.” In most cases with free apps, you
implicitly agree to trade tracking for services. You “pay” for the app by
agreeing to receive targeted ads. You can decide that this is a fair trade off,
but most companies need to track your online activities to determine which
ads to show you.
• Always read terms & conditions. Legitimate software vendors will disclose
information about how they collect and employ user information in their
terms and conditions. Most users don’t even bother to read them. If you
are particularly adamant about protecting your online privacy, it’s best to
know exactly what you are signing up for. If privacy policies are abused or
changed without user knowledge, a software vendor can seriously violate
user trust no matter its original intent.
Tips to Prevent Spyware(Additional)
Phishing Attack and Prevention
Phishing: ...
Fake Charities: ...
Criminals frequently exploit natural disasters and other
situations such as the current COVID-19 pandemic by
setting up fake charities to steal from well-intentioned
people trying to help in times of need. Fake charity
scams generally rise during times like these.
Threatening Impersonator Phone Calls: ...
IRS impersonation scams come in many forms. A
common one remains bogus threatening phone calls
from a criminal claiming to be with the Internal
Revenue Service (IRS). The scammer attempts to instill
fear and urgency in the potential victim. In fact, the IRS
will never threaten a taxpayer or surprise him or her
with a demand for immediate payment.
Social Media Scams: ...
Taxpayers need to protect themselves against social media scams, which
frequently use events like COVID-19 to try tricking people. Social media
enables anyone to share information with anyone else on the Internet.
Scammers use that information as ammunition for a wide variety of scams.
These include emails where scammers impersonate someone's family,
friends or co-workers.
EIP or Refund Theft: ...
The IRS has made great strides against refund fraud and theft in recent years,
but they remain an ongoing threat. Criminals this year also turned their
attention to stealing Economic Impact Payments as provided by the
Coronavirus Aid, Relief, and Economic Security (CARES) Act.
Senior Fraud: ...
Senior citizens and those who care about them need to be on alert for tax
scams targeting older Americans. The IRS recognizes the pervasiveness of
fraud targeting older Americans along with the Department of Justice and
FBI, the Federal Trade Commission, the Consumer Financial Protection
Bureau (CFPB), among others.
Scams targeting non-English speakers: ...
IRS impersonators and other scammers also target groups with limited
English proficiency. These scams are often threatening in nature. Some
scams also target those potentially receiving an Economic Impact
Payment and request personal or financial information from the taxpayer.
Unscrupulous Return Preparers:
Selecting the right return preparer is important. They are entrusted with a
taxpayer's sensitive personal data. Most tax professionals provide honest,
high-quality service, but dishonest preparers pop up every filing season
committing fraud, harming innocent taxpayers or talking taxpayers into
doing illegal things they regret later.
How Can You Identify a Phishing
Email?
• There are certain known patterns that can be
observed in order to prevent phishing. These
include…
• Asking for personal information
• Alarming content full of warnings and potential
consequences
• Urgent deadlines
• Offer of large financial rewards
Phishing Prevention
• Protect your Personal Information:
• Some phishing scams divert you to a fraudulent
website designed to look like your bank’s website
or similar trusted source.
• When you enter your username/password and
other information, that information is transmitted
and can abuse it later on
Beware of Suspicious Emails and Do
not Click Suspicious Links:
• Be very suspicious of any emails you receive
from trusted entities like your bank
• If the email contains a link. Don’t click on it
• Deceptive links that mimic legitimate URL
address are a common tools used in phishing
scams
• While these addresses may look official,
they usually contain inconspicuous
differences that redirect you to fraudulent
site.
• Instead of clicking on the link, type in the
web address of the institution into the
browser to access the website
Know the Common Phishing Language:
• Look out for common phishing language in
emails like “ Verify your account “
• Legitimate business will not send you an email to
ask for your login information or sensitive
personal information
• Also, look out for emails that try to convey a
sense of urgency
• Warning that your account has been
compromised, for example are a common way
to lure victims. Again, contact the company
directly to inquire about such emails rather
than using any link or other contact
information provided in the email.
• Finally be wary of any email that does not
address you directly
Avoid using public networks
• Email via public network was not encrypted
• Hackers use the username and password, save
password and other financial details.
• Even hacker setup completely free hotspot and lure
the details without sophisticated data sniffing
technologies
• Best practice is not to use public network but use the
3G/4G data connection
These are a few steps a company can take to
protect itself against phishing
• Educate your employees and conduct training
sessions with mock phishing scenarios
• Deploy a SPAM filter that detects viruses,
blank senders etc.,
• Keep all systems current with the latest
security patches and updates
• Install an antivirus solution, schedule
signature updates and monitor the antivirus
status on all equipment's
• Develop a security policy that includes
but isn’t limited to password expiration
and complexity
• Deploy a web filter to block malicious
websites
• Encrypt all sensitive company
information
Password Cracking
• A cryptographic salt is
made up of random bits
added to each password
instance before its hashing.
• Salts create unique
passwords even in the
instance of two users
choosing the same
passwords.
LM hash (also known as LanMan hash or LAN Manager hash) is a
compromised password hashing function that was the primary hash that
Microsoft LAN Manager and Microsoft Windows versions prior to
Windows NT used to store user passwords.
Passwords are typically cracked using one or
more of the following methods:
• Guessing
• Dictionary Attacks
• Brute Force
• Rainbow Tables
Guessing
• Use specific logic and try commonly used
passwords
• Many uses without the knowledge of security they
keep the password that can be remembered easily
thus easily guessed such as :
• Name of the user
• Birthdays or birth places
• Relatives
• Pets
• Favourite colours, food, places, etc.,
Dictionary Attacks
Use list of words on the interface or program that is
protecting the area that you want to gain access to
Password crackers use dictionary attack uses list of
common single words
Advanced programs use mixing in numbers or common
symbols at the beginning or at the end of the guessed
word.
Someone may use personal information ( last name,
relative name, etc.,)
Weakness of Dictionary attack is on the words supplied
by the user. ( using two words in one password can
thwart dictionary attack. Eg : John the Ripper, Cain And
Abel)
Brute force
• Systematically try all combination of password
this method is more efficient for short
passwords
• Crackers want to know the length of the
password. Then try with combination of
letters, numbers and special characters
• Though it may takes longer time finally
password can be guessed
• Eg. Oracle, Rarcrack, John the Ripper
Rainbow Tables
• Pre computed password attack
• Dictionary and Bruteforce enter password into
the locked program
• Rainbow compute hash for each word in the
dictionary and store all hashes into hash table,
retrieve the hash of password is cracked and
compare with each password hash with real
password hash.
• This method assumes hash of password to be
guessed and hashing algorithm is same between
rainbow table and password.
Rainbow tables have only become an efficient
technique recently, as the hard drive space
needed to store the hashes was slightly
cumbersome until memory became cheaper.
Passwords Cracking Protection
• Salting
One of the element of password that is becoming more and more common is
a technique called “Salting”. Salting a password means , more or less adding
bits of information to the given password before hashing it. So the password
is not merely guessable by a standard rainbow table, as the hashes are not of
simple words anymore.
Denial of Service Attacks
DoS and DDoS attacks
A Possible Case of DoS
• SBI is a leading bank in India offering banking
and financial services to public
• Imagine a situation where your SBI bank
online transactions are stopped all at a sudden
• You as a user will be frustrated
• Bank as a service provider loses credibility
• It also incurs financial losses
• One of the reason for this could be is its under
denial of service attack
Denial of Service
• Making a resource unavailable or deliberately
withholding it to make it unavailable
• Example :
– 1 Deliberate calls made to a person where he
spends lot of time in just answering
– 2. Putting a road blocker so that no vehicles
are able to use a particular road
– 3. Cutting a fiber cable and disrupting the
communication
• Denial of service do occur in many situations we
particularly study computer or data network
related denial of services
– Ex : SBI Online banking service going offline
Distributed Denial of Service
History of Denial of Service
• In Dec 1987 an employee of IBM sent an email greeting for
christmas. This email message had some malicious code in it
which automatically sent copies of itself to all in the contact
book of recipient.
• Many Dos attacks of 90 were simple and launched from a
single computer.
• In 1997- trinoo, 1998 – TFN, 2000 – TFN2K
• Year 2000 witnessed several massive scale attacks on sites like
Yahoo, Amazon , Ebay and [Link]
• American government and military sites have experienced
attacks in the past
• Most recently wikileaks site had a massive DoS attack against
its web server
ICMP based Denial of Service
Internet Control Message Protocol
• ICMP Messages are used for sending error
messages
• Also they are used for status information
• PING utility uses ICMP echo request and ICMP
ECHO REPLY messages
• In this case a powerful machine can send too
many ping messages and hog the slower machine
• One of the earliest discovered attacks in networks
• Normally ping reply messages are more than
request messages
Smurf Attack
• A variation of ICMP based attack
• Normally happens due to misconfigured network
• Many networks allow ICMP broadcast request messages
• An attacker creates a spoofed ECHO REQUEST message
with spoofed IP address( using IP of a victim)
• Every machine on the network will hear the ping message
• All these messages go to victim instead of attacker
• For the victim all these are unsolicited messages
• Spends significant amount of processing power, memory
and time in handling these ping replies
• Cannot do any useful computation there by deny services
to users
Flooding based DoS
• Send too many packets to overwhelm the
recipient
• Victim spends lot of time in responding and
processing
SYN Flood Attack
• Uses TCP connections
• Obviously too many of them make victim
irresponsive
• A SYN Flood is a common form of Denial-of-
Service (DDoS) attack that can target any
system connected to the Internet and
providing Transmission Control Protocol (TCP)
services (e.g. web server, email server, file
transfer).
• A SYN flood is a type of TCP State-Exhaustion
Attack that attempts to consume the
connection state tables present in many
infrastructure components, such as load
balancers, firewalls, Intrusion Prevention
Systems (IPS), and the application servers
themselves.
• This type of attack can take down even high-
capacity devices capable of maintaining
millions of connections.
Types of SYN Floods
• Direct attack
– Use your own machine to send SYN packets
– Need to somehow make OS not respond to SYN-ACK
packets coming from server
– Connect() socket call can be used to do this kind of attack
• Spoofing base attack
– Hide the identity of attacker
– Shields the attacker from receiving SYN-ACKs
– Spoofed source should not respond with SYN-ACK
– They will not respond in anyway
– Its more effective if a non existent IP address is chosen
– Ingress and egress filtering can be a deterrent
Other Flooding based Dos Attacks
• UDP Flood- send many UDP packets
to the target
• ICMP Flood – send many ICMP
packets to the target
• Random Flood- send packets
randomly generated
Symptoms of Manifestation
• Slow network performance
• Non availability of certain online services and
websites
• Increase in number of useless network traffic
• Consistent new IP addresses showing up
• Unusually high number of packets from a
source
• Disconnection of a wired or wireless
connections
Defending SYN Flood Attacks
• End Host Mechanisms
– Increase the backlog period
• More connections open means – refusal to new requests
• Slightly counter intuitive
– SYN Cache – initially do not create a full fledged TCB
( Trusted computing Base)
– SYN COOKIE
• Completely stateless – do not create any state or TCB till
connection is completely established
• Make the initial sequence number a function of parameters of
packet
• At most all IP spoofing mitigation techniques will
also help mitigate DoS attacks
Slowloris DDoS attack
• Slowloris is a denial-of-service attack program
which allows an attacker to overwhelm a
targeted server by opening and maintaining
many simultaneous HTTP connections
between the attacker and the target.
How does a Slowloris attack work?
• Slowloris is an application layer attack which
operates by utilizing partial HTTP requests.
• The attack functions by opening connections
to a targeted Web server and then keeping
those connections open as long as it can.
A slowloris attack occurs in 4 steps
• The attacker first opens multiple connections to
the targeted server by sending multiple partial
HTTP request headers.
• The target opens a thread for each incoming
request with the intent of closing the thread once
the connection is completed in order to be
efficient, if a connection takes too long the server
will timeout the exceedingly long connection,
freeing the thread up for the next request.
• To prevent the target from timing out the
connections, the attacker periodically send partial
request headers to the target in order to keep the
request alive in essence saying “ I am still here!
I’m Just slow, please wait for me”
• The targeted server is never able to release any of
the open partial connections while waiting for the
termination of the request. Once all available
threads are in use, the server will be unable to
respond to additional request made from regular
traffic , resulting in denial-of-service
How is a Slowloris attack mitigated?
Module 5
Cyber Threats, Attacks and Prevention
Phishing
• The term phishing comes from the analogy that Internet
scammers are using E-mail lures to fish for passwords and
financial data from the sea of Internet users. The term was
coined in 1996 by hackers who are stealing America
Online(AOL) Internet accounts by scamming passwords from
unsuspecting AOL users.
• As hackers have the tendency to replace “f” with “ph” the
term Phishing came into being.
What is it Phishing?
• Phishing – Cybercriminal attempts to steal personal and
financial information or infect computers and other devices
with malware and viruses,
– Designed to trick you into clicking a link or providing
personal or financial information,
– Often in the form of emails and websites,
– May appear to come from legitimate companies,
organizations or known individuals,
– Take advantage of natural disasters, epidemics, health
scares, political elections or timely events.
Types of Phishing
• Mass Phishing: Mass, large-volume attack intended to reach as
many people as possible.
• Spear Phishing: Targeted attack directed at specific individuals or companies
using gathered information to personalize the message and make the scam
more difficult to detect.
• Whaling: Type of spear phishing attack that targets “big fish”, including
high-profile individuals or those with a great deal of authority or access.
• Clone Phishing: Spoofed copy of a legitimate and previously delivered email,
with original attachments or hyperlinks replaced with malicious versions,
which is sent from a forged email address so it appears to come from the
original sender or another legitimate source.
• Advance-Fee Scam: Requests the target to send money or bank account
information to the cybercriminal.
Types of Phishing Attacks
Social Engineering: On your Facebook profile or LinkedIn profile, you can
find: Name, Date of Birth, Location, Workplace, Interests, Hobbies, Skills, your
Relationship Status, Telephone Number, Email Address and Favorite Food.
This is everything a Cybercriminal needs in order to fool you into thinking that
the message or email is legitimate.
Link Manipulation: Most methods of phishing use some form of deception
designed to make a link in an email appear to belong to the spoofed
organization or person. Misspelled URLs or the use of subdomains are
common tricks used by phishers. Many email clients or web browsers will
show previews of where a link will take the user in the bottom left of the
screen or while hovering the mouse cursor over a link.
Types of Phishing Attacks
Voice Phishing: Voice phishing is the criminal practice of using social
engineering over the telephone system to gain access to personal and
financial information from the public for the purpose of financial reward.
Sometimes referred to as 'vishing’, Voice phishing is typically used to steal
credit card numbers or other information used in identity theft schemes
from individuals.
Common Baiting Tactics
• Notification from a help desk or system administrator
Asks you to take action to resolve an issue with your account (e.g., email
account has reached its storage limit), which often includes clicking on a link
and providing requested information.
• Advertisement for immediate weight loss, hair growth or fitness
prowess Serves as a ploy to get you to click on a link that will infect
your computer or mobile device with malware or viruses.
• Attachment labeled “invoice” or “shipping order”
Contains malware that can infect your computer or mobile device if opened.
May contain what is known as “ransomware,” a type of malware that will
delete all files unless you pay a specified sum of money.
• Notification from what appears to be a credit card company
Indicates someone has made an unauthorized transaction on your account. If
you click the link to log in to verify the transaction, your username and
password are collected by the scammer.
• Fake account on a social media site
Mimics a legitimate person, business or organization. May also appear in the
form of an online game, quiz or survey designed to collect information from
your account.
Phishing Lure
• Claims to come from the VIT Help Desk and system
administrators.
– References VIT University.
– Calls for immediate action using threatening language.
• Includes hyperlink that points to fraudulent site.
Phishing Lure
• Claims to come from the VIT Human Resources.
– Timely call for action during annual review season
– From address includes VIT, but not .[Link](@[Link]/@[Link])
• Includes hyperlink that points to fraudulent site.
Phishing Lure
• Claims to come from
PayPal.
– Includes PayPal logo,
but from address is not
legitimate
(@[Link])
– Calls for immediate
action using
threatening language
• Includes hyperlink that
points to fraudulent
site.
Phishing Lure
• Likely an advanced- fee scam.
– Takes advantage of ongoing humanitarian crisis.
– If it sounds too good to be true.
Detect a Phishing Scam
• Spelling errors (e.g., “pessward”), lack of punctuation or poor
grammar.
• Hyperlinked URL differs from the one displayed, or it is hidden.
• Threatening language that calls for immediate action.
• Requests for personal information.
• Announcement indicating you won a prize or lottery.
• Requests for donations.
Can you detect a phishing scam?
Protect Yourself: Refuse the Bait
• STOP. THINK. CONNECT.
– Before you click, look for common baiting tactics.
– If the message looks suspicious or too good to be true,
treat it as such.
• Install and maintain antivirus software on your electronic
devices.
• Use email filters to reduce spam and malicious traffic.
Signs of a Phishing Phone Call
• You've been specially selected (for this offer).
• You'll get a free bonus if you buy our product.
• You've won one of five valuable prizes.
• You've won big money in a foreign lottery.
• This investment is low risk and provides a higher return than you can get
anywhere else.
• You have to make up your mind right away.
• You trust me, right?
• You don't need to check our company with anyone.
• We'll just put the shipping and handling charges on your credit card.
Tips to protect yourself from Phishing phone calls.
• Don’t buy from an unfamiliar company. Legitimate businesses understand that
you want more information about their company and are happy to comply.
• Always check out unfamiliar companies with your local consumer protection
agency, Better Business Bureau, state attorney general, the National Fraud
Information Center, or other watchdog groups.
• Obtain a salesperson’s name, business identity, telephone number, street address,
mailing address, and business license number before you transact business. Some
con artists give out false names, telephone numbers, addresses, and business
license numbers. Verify the accuracy of these items.
• Don’t pay for a “free prize”. If a caller tells you the payment is for taxes, he or she is
violating federal law.
• Never send money or give out personal information such as credit card numbers
and expiration dates, bank account numbers, dates of birth, or social security
numbers to unfamiliar companies or unknown persons.
• If you have been victimized once, be wary of persons who call offering to help
you recover your losses for a fee paid in advance.
What to do if you think you are receiving a Phishing Call
• Always look up the phone number in Google. Often times, others have received
these calls before and will log the number and the type of scam to different
websites. Some of the websites are [Link], [Link], and
[Link]. Users will let you know whether or not this is a scam, and
what the caller will ask for.
• Resist pressure to make a decision immediately.
• Keep your credit card, checking account, or Social Security numbers to yourself.
Don't tell them to
callers you don't know — even if they ask you to “confirm” this information. That's
a trick.
• Get all information in writing before you agree to buy.
• Beware of offers to “help” you recover money you have already lost. Callers that
say they are law enforcement officers who will help you get your money back
“for a fee” are scammers.
• Report any caller who is rude or abusive, even if you already sent them money.
Password Cracking
Three A’s of Information Security
• Security is about differentiating among authorized
accesses and unauthorized accesses.
– Confidentiality, Integrity, Availability all require this
• Authentication:
– Figures out who is accessing
• Access control:
– Ensure only authorized access are allowed
• Auditing:
– Record what is happening, to identify attacks later and
recover
User Authentication
• Using a method to validate users who attempt to access a
computer system or resources, to ensure they are authorized
• Types of user authentication:
– Something you know
• E.g., user account names and passwords
– Something you have
• Smart cards or other security tokens
– Something you are
• Biometrics
Variants of Passwords
• Password
• Passphrase
– a sequence of words or other text used for similar purpose
as password
• Passcode
• Personal identification number (PIN)
Scenarios Requiring User Authentication
• Scenarios:
Client
– Logging into a local computer
– Logging into a computer remotely
– Logging into a network
Password
– Access web sites
• Vulnerabilities can exist at client side,
server side, or communications channel.
Server
Threats to Passwords
• Eavesdropping (insecure channel between client and server)
• Login spoofing (human errors), shoulder surfing, keyloggers
• Offline dictionary attacks
• Social engineering (human errors)
– e.g., pretexting: creating and using an invented scenario (the pretext)
to persuade a target to release information or perform an action and is
usually done over the telephone
• Online guessing (weak passwords)
Guessing Attacks: Two Factors for Password
Strength
• The average number of guesses the attacker must make to find
the correct password
– determined by how unpredictable the password is,
including how long the password is, what set of
symbols it is drawn from, and how it is created.
• The ease with which an attacker can check the validity of a
guessed password
– determined by how the password is stored, how the
checking is done, and any limitation on trying passwords
Password Entropy
• The entropy bits of a password, i.e., the information entropy
of a password, measured in bits, is
– The base-2 logarithm of the number of guesses needed
to find the password with certainty
– A password with, say, 42 bits of strength calculated in this
way would be as strong as a string of 42 bits chosen
randomly.
– Adding one bit of entropy to a password doubles the
number of guesses required.
KeyLogging
• Threats from insecure client side
• Keystroke logging (keylogging) is the action of tracking (or logging) the keys
struck on a keyboard, typically in a covert manner so that the person using the
keyboard is unaware that their actions are being monitored.
• Software –based:
– key-stroke events, grab web forms, analyze HTTP packets
• Hardware-based:
– Connector, wireless sniffers, acoustic based
• Defenses:
– Anti-spyware, network monitors, on-screen soft keyboard, automatic form
filler, etc.
• In general difficult to deal with once on the system
Using Passwords Over Insecure Channels
• One-time passwords:
– Each password is used only once
– Defend against passive adversaries who eavesdrop and
later attempt to impersonate
• Challenge response:
– Send a response related to both the password and a
challenge
• Zero knowledge proof of knowledge:
– Prove knowledge of a secret value, without leaking any
info about the secret
Passwords
Methods of Attack
• Dictionary Attack:
– Quick technique that tries every word in a specific dictionary
• Hybrid Attack:
– Adds numbers or symbols to the end of a word
• Brute Force Attack:
– Tries all combinations of letters, numbers & symbols
• Popular programs for Windows password cracking:
– LC4
– Sam Inside
– Crack
– John the Ripper (JTR)
Passwords
Dictionary Attack
• Password file • Dictionary attack is possible
/etc/passwd is world- because many passwords
readable come from a small dictionary
– Contains user IDs and group – Attacker can compute H(word)
for every word in the dictionary
IDs which are used
and see if the result is in the
by many system programs password file
– With 1,000,000-word dictionary
and assuming 10 guesses per
second, brute-force online
attack takes 50,000 seconds (14
hours) on average
– This is very conservative.
Offline attack is much
faster!
Passwords
Security Levels
Filing System
Clear text
Dedicated Authentication Server:
Clear text
Encrypted:
Password + Encryption = bf4ee8HjaQkbw
Hashed:
Password + Hash function =
aad3b435b51404eeaad3b435b51404ee
Salted Hash:
(Username + Salt(random string of
characters) + Password) + Hash
function =
e3ed2cb1f5e0162199be16b12419c012
Passwords
Hashing
• Instead of user password, store • Hash function H must have some
hash of password properties
• When user enters password, – One-way: given H(password),
hard to find password
compute its hash and compare
– No known algorithm better
with entry in password file
than trial and error
– System does not store actual – Collision-resistant: given
passwords! H(password1), hard to find
password2 such that
H(password1)=H(password2)
– It should even be hard to
find any pair p1,p2 s.t.
H(p1)=H(p2)
Passwords
Salting
• Salting requires adding a random piece of data and to the password before
hashing it.
– This means that the same string will hash to different values at different times
– Users with the same password have different entries in the password file
– Salt is stored with the data that is encrypted
• Hacker has to get the salt add it to each possible word and then rehash the
data prior to comparing with the stored password.
Passwords
Salting Advantages
• Without salt, attacker • With salt, attacker
can pre-compute must compute hashes
hashes of all dictionary of all dictionary
words once for all words once for each
password entries password entry
– Same hash function on – With 12-bit random
all UNIX machines salt, same password
– Identical passwords can hash to 212
hash to identical different hash values
values; one table of – Attacker must try all
hash values can be dictionary words for
used for all password each salt value in the
files password file
Passwords
Iteration Count
• The same password can be rehashed many times over to
make it more difficult for the hacker to crack the password.
• This means that the precompiled dictionary hashes are not
useful since the iteration count is different for different
systems
– Dictionary attack is still possible!
Passwords
Shadow
• Utilized in UNIX systems
• Store hashed passwords in
/etc/shadow file which is only
readable by system administrator
(root)
• Add expiration dates for passwords
• Early Shadow implementations on
Linux called the login program which
had a buffer overflow!
Passwords
Authentication Protocols
• Set of rules that governs the • TIME STAMP
communication of data related – The authentication from the
to authentication between the client to server must have time-
server and the user stamp embedded
• TRANSFORMED PASSWORD – Server checks if the time is
– Password transformed using reasonable
one way function before – Protects against replay
transmission
– Depends on synchronization of
– Prevents eavesdropping but
clocks on computers
not replay • ONE-TIME PASSWORD
• CHALLENGE-RESPONSE – New password obtained by
– Server sends a random value passing user-password through
(challenge) to the client one-way function n times which
along with the
authentication request. This keeps incrementing
must be included in the – Protects against replay as well
response as eavesdropping
– Protects against replay
Passwords
Challenge Response
• User and system share a – Freshness: if challenge is fresh
secret key and unpredictable, attacker on
the network cannot replay an
• Challenge: system presents old response
user with some string – For example, use a fresh
random number for each
• Response: user computes
challenge
response based on secret
• Good for systems with pre-
key and challenge
installed secret keys
– Secrecy: difficult to recover – Car keys; military friend-or-foe
key from response identification
– One-way hashing or
symmetric encryption
work well
Passwords
Improving Security
•Add biometrics • Rely on the difficulty of
– For example, keystroke computer vision
dynamics or voiceprint – Face recognition is easy for
– Revocation is often a problem humans, hard for machines
with biometrics – Present user with a sequence
of faces, he must pick the
•Graphical passwords right face several times in a
– Goal: increase the size of row to log in
memorable password space • Other examples
– Click on a series of pictures in
order
– Drawing a picture
– Clicking four correct points
on a picture
Passwords
Personal Token Authentication
• Personal Tokens are hardware – Storage Token: A secret value that is
devices that generate unique stored on a token and is available after
strings that are usually used in the token has been unlocked using a
conjunction with passwords for PIN
authentication – Synchronous One-time Password
Generator: Generate a new password
• A variety of different physical periodically (e.g. each minute) based
forms of tokens exist on time and a secret code stored in
– e.g. hand-held devices, Smart the token
Cards, PCMCIA cards, USB – Challenge-response: Token computes
tokens a number based on a challenge value
• Different types of tokens exist: sent by the server
– Digital Signature Token: Contains the
digital signature private key and
computes a digital signature on a
supplied data value
Passwords
Biometric Authentication
• Uses certain biological • Different techniques exist
characteristics for – Fingerprint Recognition
authentication – Voice Recognition
– Biometric reader – Handwriting Recognition
measures physiological – Face Recognition
indicia and compares – Retinal Scan
them to specified values – Hand Geometry
Recognition
– It is not capable of
securing information
over the network
Passwords
Fingerprint Authentication
• Unique patterns in
peoples fingerprints are
used for unique
identification.
• Most tested of all
biometric systems.
• Commonly used in crime
labs
for forensic investigations.
Passwords
Iris Authentication
• The scanning process takes
advantage of the natural patterns
in people's irises, digitizing them
for identification purposes.
– Probability of two irises producing
exactly the same code: 1 in 10 to
the 78th power
– Independent variables (degrees of
freedom) extracted: 266
– IrisCode record size: 512 bytes
– Operating systems compatibility:
DOS and Windows (NT/95)
– Average identification speed
(database of 100,000 IrisCode
records): one to two seconds
Passwords
Protection/Detection
Protection:
– Disable storage of LAN Manager hashes.
– Configure both Local and Domain Account Policies
(Password & Account Lockout Policies).
– Audit access to important files.
– Implement SYSKEY security on all systems.
– Set BIOS to boot first from the hard drive.
– Password-protect the BIOS.
– Enforce strong passwords!
– Change your passwords frequently.
– Use two or three factor authentication.
– Use one time passwords.
Passwords
Ten Common Mistakes
1. Leaving passwords blank or unchanged from default
value.
2. Using the letters p-a-s-s-w-o-r-d as the password.
3. Using a favorite movie star name as the password.
4. Using a spouse’s name as the password.
5. Using the same password for everything.
6. Writing passwords on post-it notes.
7. Pasting a list of passwords under the keyboard.
8. Storing all passwords in an Excel spreadsheet on a PDA
or inserting passwords into a rolodex.
9. Writing all passwords in a personal diary.
10. Giving the password to someone who claims to be the
system administrator.
Introduction – What is Identity Theft?
• Stealing someone’s personal information and using it
to assume someone’s identity.
• The fraudulent use of personal information to open new
accounts and/or purchase items using existing accounts.
How Personal Information is Gathered
• Dumpster diving:
– Personal information, when
stolen from your property
either through dumpster
diving or theft, provide a
criminal with a wealth of
information with which to
open new accounts or use
existing accounts.
Shredder – Necessary Equipment
• To minimize your risk of
identity theft, be sure to
shred all unused
convenience checks, credit
card offers, credit card
receipts, bank statements,
pre- approved loan offers,
and canceled checks.
How Personal Information is Collected Through
Legitimate Business Records
• Recently personal medical files for hundreds of
patients were found discarded outside a medical
clinic. Identity thieves could have used these files.
• Businesses are required by law to protect their
client's personally identifying information and to
discard these files safely.
• Thieves steal valuable personal information from
customer files and personnel files.
How to Prevent Identity Theft
Part One
• Education • Make online purchases
• Coalition on Online only with companies
Identity Theft having secure
• Padlock your credit file connections
• Check your credit report • Never give out your
annually personal information over
the phone unless you
• Share personal initiated the call.
information only with
people and companies • Never have your Social
you trust Security number printed
on your checks
How to Prevent Identity Theft
Part Two
• Never leave personal • Never keep passwords to
information on your financial data on your
computer without having computer.
a firewall in place. • Likewise never keep your
• After opening your mail, ATM or credit card pin
shred all unused credit numbers in your wallet or
card offers, unused your car. If either are
convenience checks, and stolen, the thieves have
any other pieces of mail instant access to your
that include personally accounts.
identifying information.
How to Prevent Identity Theft
Part Three
• Never use your mother's • If the amount of mail you
maiden name, the last normally receive drops
four digits of your Social suddenly; contact your
Security number, your post office to make sure
birth date, your pet's no one has fraudulently
name, or any other easily filed a change of address
recognized letters and card for your address.
numbers as your pin
number or passwords.
How to Prevent Identity Theft
Part Four
• Review all credit card • Shred all expired
transactions each credit cards before
month when you receive putting them in the
your credit card trash.
statement.
How to Prevent Identity Theft
Part Five
• Install a locking mailbox to ensure the
security of mail delivered to your home.
• Mail all payments and other documents with
personal or financial information from the
post office or at a postal drop box, never from
your mailbox.
• Thieves may take your checks from
unsecured mailboxes and bleach them so
they may be used again.
Prevention of Identity Theft by Education
• People must be educated as to the value of
information.
• They must be trained to protect information (even
if the information they have access to appears to
be of relatively low value).
• People must be made aware of what social
engineering is and how social engineers operate.
Checking a Web Site’s Security Certificate
• Check the security certificates for web sites from which you
purchase products or do other financial transactions.
• Go to the web site and click on the VeriSign Secure Site link to verify
that the security certificate is in the same name as the company.
• If the company name listed there doesn't match the company owning
the site, be wary of submitting financial information. Security
certificates are sometimes held in the parent company’s name.
Checking for Secure Web Sites
• Check the URL (the web address) of the web site you
are doing business with.
• Whenever you are entering your credit card
information or other financial information when
ordering online, the address should display https,
rather than http, if you are connecting to a secure
web site.
ex: [Link]
Checking Security Features When Using Netscape
Navigator
• To check the security in
Netscape, look at the padlock in
the lower right corner.
– unlocked = not secure
– locked = secure
• To check the level of encryption,
left click the lock in the lower
right-hand corner of the page. A
pop up window will appear and
tell you whether or not the page
you are viewing is encrypted
and what type of encryption is
being used.
Checking Security Features When Using Internet
Explorer
• When using Internet Explorer as your browser,
open the page whose security you want to check.
• Right click on the page and then go to properties.
• When you click properties, a pop up window will appear
with information on the site's security.
What to Do If You Become a Victim of Identity Theft
• Call the Federal Trade Commission’s Identity Theft Toll-
free Hotline (877 – IDTHEFT)
• Call all three of the major credit bureaus
– Experian - 1-888-397-3742
– EquiFax - 1-800-525-6285
– TransUnion - 1-800-680-7289
• For identity theft involving student information or federal
education funds, contact U.S. Department of Education, Office
of Inspector General
– 1-800-647-8733
What to Do If You Become a Victim of Identity Theft
• File a police report as soon as possible.
• Contact your creditors for all affected accounts,
– "A fraud alert" will be automatically placed on each of
your credit reports within 24 hours. This alerts
creditors to call you for permission before any new
accounts are opened in your name.
– Not all creditors pay attention to "fraud alerts." You
need to stay vigilant for any new accounts that may
be opened.“
What to Do If You Become a Victim of Identity Theft
• Also make your complaints in writing, asking each creditor
to provide you and any law enforcement agencies
investigating the crime(s) with copies of all documentation
that shows fraudulent activity.
• By making your complaint in writing, you are
documenting the time and date when you became aware
of the incident. This may protect you from responsibility
for additional charges.
Denial of Service Attacks
Understanding to Denial of Services
How can a service be denied?
• Using up resources is the most common approach.
• Several ways..
– Crash the machine
– Put it into an infinite loop
– Crash routers on the path to the machine
– Use up a machine resource
– Use up a network resource
– Deny another service needed for this one (e.g. DNS)
What is Denial of Service?
• Denial of Service (DoS):
– Attack to disrupt the authorized use of networks,
systems, or applications.
• Distributed Denial of Service (DDoS):
– Employ multiple compromised computers to perform a
coordinated and widely distributed DoS attack.
DoS Single Source
DDoS
Collateral
damage points
DDoS Attack Traffic (1)
One Day Traffic Graph
DDoS Attack Traffic (2)
One Week Traffic Graph
DDoS Attack Traffic (3)
One Year Traffic Graph
DDoS Botnets
• Botnet: Collection of compromised computers that are
controlled for the purposes of carrying out DDoS attacks or
other activities.
• Can be large in number.
• Systems join a botnet when they become infected by
certain types of malware.
– Like a virus, but instead of harming the system, it wants to
take it over and control it.
– Through email attachments, website links, or IM links.
– Through unpatched operating system vulnerabilities.
Botnets Modus Operandi
multi-tier design
Zombies
Zombies
Bot: Direct control
Bot: Indirect control
Cost of DDoS Attacks
• Victims of (D)DoS attacks:
– Service-providers (in terms of time, money, resources,
good will).
– Legitimate users (deprived of availability of service).
• Hard to quantify:
– Incomplete data – Companies reluctant to admit they
have been victimized.
– Lost business.
– Lost productivity.
Why? Who?
⚫Several motives:
⚫Earlier attacks were proofs of concepts
⚫Pseudo-supremacy feeling
⚫Eye-for-eye attitude
⚫Political issues
⚫Competition
⚫Hired
⚫Levels of attackers:
⚫Highly proficient attackers who are rarely identified
or caught
⚫Script-kiddies
The DDoS Landscape
2002 DNS DoS Attacks
ICMP floods 150 Kpps (primitive attack)
Took down 7 root servers (two hours)
DNS root servers
2009 DDoS on Twitter
• Hours-long service outage
– 44 million users affected
• At the same time Facebook, LiveJournal, and YouTube were
under attacked
– some users experienced an outage
• Real target: a Georgian blogger
DDoS on Mastercard and Visa
• December 2010
• Targets: MasterCard, Visa, Amazon, Paypal,
Swiss Postal Finance, and more.
⚫ Attack launched by a group of vigilantes called
Anonymous (~5000 people)
⚫ DDoS tool is called LOIC or “Low Orbit Ion Cannon”
⚫ Bots recruited through social engineering
⚫ Directed to download DDoS software and take instructions
from a master
⚫ Motivation: Payback, due to cut support of WikiLeaks after their
founder was arrested on unrelated charges
The new DDoS tool by Anonymous
• New operation is beginning
• A successor of LOIC
• Low Orbit Ion Cannon (LOIC) is an open-source network
stress testing tool.
• Using SQL and .js vulnerability, remotely deface page
• May be available in this September 2011
DDoS Attack Classification
DOS attack list
• Flood attack:
– TCP SYN flood
– UDP flood
– ICMP (PING) flood
– Amplification (Smurf, Fraggle since 1998)
• Vulnerability attack:
– Ping of Death (since 1990)
– Tear Drop (since 1997)
– Land (since 1997)
Flooding attack
• Commonly used DDoS attack.
• Sending a vast number of messages whose processing consumes some key
resource at the target.
• The strength lies in the volume, rather than the content.
• Implications :
• The traffic look legitimate
• Large traffic flow large enough to consume victim’s resources
• High packet rate sending
Vulnerability DoS attack
• Vulnerability : A bug in implementation or a bug in a
default configuration of a service.
• Malicious messages (exploits) : unexpected input that
utilize the vulnerability are sent.
• Consequences :
• The system slows down or crashes or freezes or reboots
• Target application goes into infinite loop
• Consumes a vast amount of memory
Flooding attack
TCP SYN flood
SYN RQST
server
SYN ACK
client
zombie victim
Waiting
queue
Zombies
SYN ACK overflows
Spoofed SYN RQST
Flooding attack
Smurf attack
• Amplification attack:
– Sends Internet Control
Message
Protocol (ICMP) echo
request to network.
– Amplified network flood.
– widespread pings with faked return
address (broadcast address).
– Network sends response to victim
system.
– The "smurf" attack's cousin is
called "fraggle", which uses UDP
echo packets in the same fashion.
DoS : Smurf
A B
Ping Broadcast
Src Addr : B
Dst Addr : Broadcast
Flooding attack
DoS : Fraggle
A B
Infinite Loop!
UDP Broadcast
src port : echo
dest port: chargen port
Src Addr : B
Dst Addr : Broadcast
Vulnerability DoS attack
Ping of Death
• Sending over size ping packet to victim
– >65535 bytes ping violates IP packet length
– Causes buffer overflow and system crash
• Problem in implementation, not protocol
• Has been fixed in modern OSes
– Was a problem in late 1990s
Vulnerability DoS attack
Teardrop
• A bug in their TCP/IP fragment reassembly code.
• Mangle IP fragments with overlapping, over-sized payloads to the
target machine.
• Crash various operating systems.
Vulnerability DoS attack
LAND
• A LAND (Local Area Network Denial) attack
• First discovered in 1997 by “m3lt”
– Effect several OS :
• AIX 3.0
• FressBSD 2.2.5
• IBM AS/400 OS7400 3.7
• Mac OS 7.6.1
• SUN OS 4.1.3, 4.1.4
• Windows 95, NT and XP SP2
• IP packets where the source and destination address are set to address
the same device.
– The machine replies to itself continuously
– Published code land.c
LAND
Well known old DDoS Tools
Botnet Communication Attack Type Encrypted
Type Communication?
Trinoo or trin00 TCP/UDP UDP Flood No
Tribe Flood Network TCP/UDP/ICMP Multiple No
(TFN)
TFN2K TCP/UDP/ICMP Multiple No
Randomized Randomized
Stacheldraht TCP/UDP/ICMP Multiple Yes
Randomized Randomized
DDoS Defense
Are we safe from DDoS?
• My machine is well secured:
– It does not matter. The problem is not your machine but
everyone else.
• I have a Firewall:
– It does not matter. We slip with legitimate traffic or we
bomb your firewall.
• I use VPN:
• It does not matter. We can fill your VPN pipe.
• My system is very high provision:
– It does not matter. We can get bigger resource than you
have.
Why DoS Defense is difficult
• Conceptual difficulties:
– Mostly random source packet
– Moving filtering upstream requires communication
• Practical difficulties:
– Routers don’t have many spare cycles for analysis/filtering
– Networks must remain stable—bias against infrastructure
change
– Attack tracking can cross administrative boundaries
– End-users/victims often see attack differently (more
urgently) than network operators
• Nonetheless, need to:
– Maximize filtering of bad traffic
– Minimize “collateral damage”
Defenses against DoS attacks
• DoS attacks cannot be prevented entirely.
• Impractical to prevent the flash crowds without
compromising network performance.
• Three lines of defense against (D)DoS attacks:
– Attack prevention and preemption
– Attack detection and filtering
– Attack source traceback and identification
Attack prevention
• Limit ability of systems to send spoofed packets:
– Filtering done as close to source as possible by
routers/gateways
– Reverse-path filtering ensure that the path back to
claimed source is same as the current packet’s path
• Ex: On Cisco router “ip verify unicast reverse-path”
command
• Rate controls in upstream distribution nets:
– On specific packet types
– Ex: Some ICMP, some UDP, TCP/SYN
• Block IP broadcasts.
Responding to attacks
• Need good incident response plan:
– With contacts for ISP (Internet Service Provider)
– Needed to impose traffic filtering upstream
– Details of response process
• Ideally have network monitors and IDS(Intrusion Detection System
):
– To detect and notify abnormal traffic patterns
• Identify the type of attack:
– Capture and analyze packets
– Design filters to block attack traffic upstream
– Identify and correct system application bugs
• Have ISP trace packet flow back to source:
– May be difficult and time consuming
– Necessary if legal action desired
• Implement contingency plan.
• Update incident response plan.
DDoS Attack Trends
• Attackers follow defense approaches, adjust their code to bypass
Ddefenses.
• Use of subnet spoofing defeats ingress filtering.
• Use of encryption and decoy packets, IRC or P2P obscures
master- slave communication.
• Encryption of attack packets defeats traffic analysis and signature
detection.
• Pulsing attacks defeat slow defenses and traceback
• Flash-crowd attacks generate application traffic.
Implications For the Future
• More complex attacks.
• Recently seen trends:
– Larger networks of attack machines
– Rolling attacks from large number of machines
– Attacks at higher semantic levels
– Attacks on different types of network entities
– Attacks on DDoS defense mechanisms
• Need flexible defenses that evolve with attacks.
SQL Injection
Malicious code is embedded in SQL statements via web page input.
Web Application using database
SQL Injection
• SQL injection is a web security vulnerability that allows an
attacker to interfere with the queries that an application
makes to its database.
• It generally allows an attacker to view data that they are not
normally able to retrieve. This might include data belonging
to other users, or any other data that the application itself is
able to access.
• In many cases, an attacker can modify or delete this data,
causing persistent changes to the application's content or
behavior.
Example
What is the impact of a successful SQL injection
attack?
• A successful SQL injection attack can result in unauthorized
access to sensitive data, such as passwords, credit card details,
or personal user information.
• Many high-profile data breaches in recent years have been the
result of SQL injection attacks, leading to reputational damage
and regulatory fines.
• In some cases, an attacker can obtain a persistent backdoor
into an organization's systems, leading to a long-term
compromise that can go unnoticed for an extended period.
• Although there are infinite possible ways of framing an
attack, they can be classified under five types:
– Tautology Attack
– Piggy-Backed Queries
– Union Query
– Illegal/Logically Incorrect Queries
– Inference
Tautology Attack
• In a tautology-based attack, the code is injected using the
conditional OR operator such that the query always evaluates
to TRUE.
• Tautology-based SQL injection attacks are usually bypass user
authentication and extract data by inserting a tautology in
the WHERE clause of a SQL query.
• The query transform the original condition into a tautology,
causes all the rows in the database table are open to an
unauthorized user.
Piggy-Backed Queries
• This type of attack is different than others because the
hacker injects additional queries to the original query, as a
result the database receives multiple SQL queries.
• The first query is valid and executed normally, the
subsequent queries are the injected queries, which are
executed in addition to the first.
Union Query
• This type of attack can be done by inserting a UNION query
into a vulnerable parameter which returns a dataset that is
the union of the result of the original first query and the
results of the injected query.
• The SQL UNION operator combines the results of two or more
queries and makes a result set which includes fetched rows
from the participating queries in the UNION.
Illegal/Logically Incorrect Queries
• In this type of injection an attacker is trying gather
information about the type and structure of the back-end
database of a Web application.
• The attack is considered as a preliminary step for further
attacks.
• If an incorrect query is sent to a database, some application
servers return the default error message and the attacker
takes the advantage of this weakness.
Inference
• In this type of injection, the attack is applied on well-secured databases
which do not return any usable feedback or descriptive error messages.
• The attack is normally created in the style of the true false statement.
• After finding the vulnerable parameter, the attacker injects various
conditions (that he wants to know whether they are true or false) through
query and carefully observe the situation. If statement evaluates to true,
the page continues to function normally. If false, the page behaves
significantly different from the normally functioning. This type of injection
is called Blind Injection.
• There is another type of inference attack which is called Time Attack. In
this method, an attacker designs a conditional statement and inject
through the vulnerable parameter and gather information based on time
delays in the response of the database.
Consequences
Consequences of a SQL injection attack could be:
• Loss of data confidentiality
• Loss of data integrity
• Loss of data
• Compromise of the entire network