More than two days after experiencing a complete outage as a result of a distribute denial-of-service (DDoS) attack, Twitter and other social networking sites such as Facebook are still battling a surge in traffic related to the attack. Twitter has taken some steps to mitigate the spike in traffic and ensure that the site is not knocked offline again, but some of those steps are having an impact on third-party tools that link to Twitter through API's (application programming interface).
Evidence gathered thus far from Twitter and other sites targeted by the DDoS attacks seems to suggest that the attack is actually a politically motivated attack aimed at silencing a Georgian activist. The victim, known by the online handle Cyxymu, uses blogs and social media sites like Twitter and Facebook to express views related to the tensions between Russia and Georgia. In a blog post, Mikko Hypponen, Chief Research Officer of Internet security firm F-Secure, said "Launching DDoS attacks against services like Facebook is the equivalent of bombing a TV station because you don't like one of the newscasters.
[ Learn how to secure your systems with Roger Grimes' Security Adviser blog and newsletter, both from InfoWorld. ]
To defend itself against the ongoing DDoS attack, Twitter has implemented various defensive actions, some of which are blocking third-party Twitter applications from being able to connect with Twitter API's. The mitigating steps are also affecting the ability of many users to post to their Twitter accounts via SMS (short message service) text messages.
Twitter is working diligently for a more permanent solution that doesn't impact third-party applications or SMS messaging. In the meantime though, Twitter has stated that as long as the attacks continue they can't guarantee that things will get better or provide any assurances that they won't get worse. The best they can do is to promise to do everything they can as fast as they can to ensure the site remains available.
Other steps that can be taken involve identifying and isolating sources of attack traffic and simply dropping all incoming packets from those sources. That can have some affect, but when an attack leverages a botnet and the attack traffic is literally coming from hundreds of thousands of sources simultaneously it quickly becomes cumbersome and impractical to try and filter the traffic in this way. Another temporary solution could be to filter all traffic intended for the suspected victim, Cyxymu, and block that so that it does not hog the network bandwidth or server processing horsepower.
When the dust settles, Twitter should look at ways they can build scalability and redundancy into their network to better withstand similar attacks in the future. Stuart McClure, VP of Operations and Strategy for McAfee's Risk and Compliance Unit and co-author of Hacking Exposed 6, says "Many of these newly emerging social engineering sites weren't built with security or high performance scalability in mind. They need to look at their current and desired states and make tough decisions that migrate them from homegrown applications to highly available cornerstones of commerce."
Tony Bradley is an information security and unified communications expert with more than a decade of enterprise IT experience. He provides tips, advice and reviews on information security and unified communications technologies on his site at tonybradley.com.
Get the independent advice and expertise you need to support a virtual workforce.
The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now »Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.
Download now »A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.
Download now »
Sign up to receive InfoWorld Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »