This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Akami - Attack traffic overview ...

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

See the site - use menu at top of display "Modes > Attacks":

- http://www.akamai.com/html/technology/dataviz1.html
2009.10.27 - 36% above normal …!

- http://www.akamai.com/html/technology/real…ethodology.html
"Attack Traffic:
Akamai measures attack traffic in real time across the Internet with our diverse network deployments. We collect data on the number of connections that are attempted, the source IP address, the destination IP address and the source and destination ports in real time. The packets captured are generally from automated scanning trojans and worms looking to infect new computers scanning randomly generated IP addresses. The attack traffic depicts the total number of attacks over the last twenty-four hours.
Values are measured in attacks per 24 hours (attacks/24hrs). Regions are displayed as countries or states."
___

- http://www.v3.co.uk/v3/news/2252011/trend-micro-sees-blocked
27 Oct 2009 - "The sheer scale of the cyber security threat to businesses was highlighted again today, after new statistics from security vendor Trend Micro revealed that its Smart Protection Network (SPN) now blocks an average of more than four billion threats a day. SPN is Trend Micro's newest technology designed to fight today's threats as effectively as possible, combining cloud-based reputation technology with behavioural analysis techniques. The system stops many of the threats in the cloud, crucially negating the problems associated with traditional security tools, such as eating up processing power and network bandwidth… SPN has been up and running for 16 months, but saw significant growth between the third quarter of 2008 and the second quarter of 2009, when the number of global user queries jumped 289 per cent to over 29 billion a day. The number of threats blocked over the same period rose 277 per cent to just over four billion, the company said. Threats in this instance include infected files, as well as web destinations reached through the browser and infected PCs trying to connect to a resource on the internet…"

:( :blink:
29 billion queries per day is only 5 per every man, woman, and child on the face of the earth. 4 billion threats detected…. hey that's less than one for each of us. What's to worry? :P
Just having fun with the numbers. :) When you look at it another way 4 billion detections, most of them worms and trojans, it is easy to realize how it can be so profitable for the bad-guys. And (off-topic) how unhappy we all should be with the online ad merchants that fail to screen content or even make a rudimentary investigation of the source IP and paying company before blindly snatching the ad money.

.. online ad merchants that fail to screen content or even make a rudimentary investigation of the source IP and paying company before blindly snatching the ad money.

Good grief, Charlie Brown! 'Hadn't thought much about that. But giving it some thought, I guess all they're thinking about nowadays is being "PCI compliant"…

:(
As I think you've posted elsewhere, Google, and Bing, and Yahoo, etc make a huge portion of their revenue from pay per click and other sponsored ad listing, not even considering banner and display ads. I admire what those search engine/providers have done for the internet, but their is no incentive whatsoever for them to refuse money. And since none of us are likely to be in favor of "regulation", they get a free pass and smile apologetically all the way to the bank.
"Possible" solution would be to open it up to Website Owners to have "complete" control of which random sponsored ads are allowed to be displayed on their own Website. Put the burden on the Website. I know that help sites like this one do their level best to prevent the worst of the worst from being displayed. But after you use up your limited number of pre-emptory challenges, the sponsoring source can run pretty much whatever they are being paid to run. When prospective advertisers sign up, they could be told that their ads will be available to run randomly and without restriction, except at the discretion of the subscribing Website Owners. Therefore, the prospective advertiser would have to clean-up-their-act, to meet the criterion of their projected audiences. As a sponsoring Website, I'd even be willing to pay a premium or accept less revenue, in order to have unlimited pre-emptory challenges. There would still be sites that would allow "all comers" but at least reputable sites like WTT could refuse random ads that push the very carp** that the site volunteers work so hard to remove from victim machines.
So France and the UK are taking the worst hits, right now? And here in my little center of the Sacramento Valley things are heating up? Why Me? :rofl:
FYI…

Attacks at 191% above normal
- http://www.akamai.com/html/technology/dataviz1.html
2010.06.04 @07:16AM edt - 651 attacks / 24 hours …

- http://www.akamai.com/html/technology/real…ethodology.html
Attack Traffic: … The packets captured are generally from automated scanning trojans and worms looking to infect new computers scanning randomly generated IP addresses. The attack traffic depicts the total number of attacks over the last twenty-four hours. Values are measured in attacks per 24 hours (attacks/24hrs). Regions are displayed as countries or states…"

:ph34r: :ph34r:
Cool map presentation. I may be jadded, and I may not be accurately understanding the representation, but somehow it is not surprise to me that folks in New York and my home state of California are being attacked at an increasingly higher rate than other areas. "Easy pickings"? :D
FYI…

Akami - Attack traffic at 76% above normal
- http://www.akamai.com/html/technology/dataviz1.html
2010.06.15 @13:16 edt - 641 attacks / 24 hours …

- http://www.symantec.com/connect/blogs/zero-day-connection
June 14, 2010 - "… The term Advanced Persistent Threat (APT*) is fashionable at the moment — and we hesitate to use it — but an active attacker that uses a zero-day to target their victims over such a long period of time seems to be the kind of attacker that this term applies to…"
* http://en.wikipedia.org/wiki/Advanced_Persistent_Threat

:ph34r: