{"id":24837,"date":"2019-03-20T12:52:06","date_gmt":"2019-03-20T12:52:06","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=24837"},"modified":"2019-03-22T09:41:25","modified_gmt":"2019-03-22T09:41:25","slug":"intelligence-shows-that-iot-bot-attacks-are-contining","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/03\/20\/intelligence-shows-that-iot-bot-attacks-are-contining\/","title":{"rendered":"Intelligence shows that IoT bot attacks are contining"},"content":{"rendered":"<p>NETSCOUT Arbor, which specialises in advanced Distributed Denial of Service (DDoS) protection solutions, has shared intelligence released by its security research and analysis team &#8211; Arbor\u2019s Security Engineering and Response Team (ASERT).<\/p>\n<p>Bryan Hamman, Territory Manager for Sub-Saharan Africa at NETSCOUT Arbor, said: \u201cEarlier this year, we released news of the trends we foresaw happening in 2019 and one of our predictions was that botnet attacks via the Internet of Things devices are set to increase. As it turns out, we were spot on.\u201d<\/p>\n<p><strong>IoT round-up<\/strong><\/p>\n<p>Any embedded device that runs an operating system and has networking capabilities can be considered an IoT device, according to Hamman.<\/p>\n<p>Most consumer IoT devices are vulnerable to hard code, default credential attacks and buffer overflows, which basically turn their linked device into a DDoS attacking machine \u2013 and one that is already conveniently connected to thousands of other devices on the same network.<\/p>\n<p>\u201cOur challenge comes in when patches are released in that they are rarely applied,\u201d added Hamman.<\/p>\n<p>\u201cConsumers don\u2019t think of security when they plug their IoT devices in or switch them on, and with nearly 27 billion connected devices in 2017 rising to an anticipated 125 billion by 2030, IoT devices are increasingly attractive to malware designers.<\/p>\n<p>\u201cTo effectively plot their \u2018journey\u2019, our team created a host of IoT honeypots, which are, basically, computers built with one purpose in mind and that is to mimic a likely target for attackers. Our ASERT team uses them to detect attacks and to gain information about how cybercriminals operate.<\/p>\n<p>\u201cIn this case, telemetry from our honeypots showed that the number of exploit attempts originating from bots continues to increase. In fact, we witnessed a two-fold increase in the number of exploit attempts from December 2018 to January 2019 \u2013 a massive 218% increase with more and more botnets attempting to exploit IoT device vulnerabilities.\u201d<\/p>\n<p><strong>An old foe evolves<\/strong><\/p>\n<p>The most common exploit, called CVE-2014-8361, dominated the list of IoT exploits to hit the ASERT honeypots over the two-month period. This exploit vector was publicly disclosed in April 2015, tracing back to several high profile IoT botnets like Satori and JenX, both of which can be traced back to an old \u2018friend\u2019 \u2013 Mirai &#8211; proving that the shelf life for an IoT-based exploit can last for years.<\/p>\n<p>\u201cIn fact, when reviewing the payloads for these attacks, we found that most of the malware being delivered is a Mirai variant, again proving that you can teach an old dog new tricks,&#8221; said Hamman.<\/p>\n<p>\u201cDue to the sheer number of IoT devices connected to the Internet, finding vulnerable devices is easy and quick and it doesn\u2019t take a significant amount of effort to create a large IoT botnet and create havoc, as we saw with the DDoS attacks conducted by Mirai in 2016.<\/p>\n<p>\u201cAs we roll in to 2019, ASERT research assures us that we will continue to see an uptick in the use of IoT based vulnerabilities with the ease of updating botnet source code like Mirai to take advantage of these vulnerabilities playing a significant role in this permeation.\u201d<\/p>\n<p>As vendors try and address these issues, so too will IoT botnet operators evolve their approach.\u00a0 So, as security practitioners, said Hamman, we must learn from these tactics and figure out how we can educate consumers in better defending their property.<\/p>\n<p>\u201cAnd, as always, it\u2019s critical that IoT security be part of an organisation\u2019s security programme \u2013 with continual and vigilant patching, testing, monitoring, and incident response protocols,\u201d he said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NETSCOUT Arbor, which specialises in advanced Distributed Denial of Service (DDoS) protection solutions, has shared intelligence released by its security research and analysis team &#8211; Arbor\u2019s Security Engineering and Response Team (ASERT). Bryan Hamman, Territory Manager for Sub-Saharan Africa at NETSCOUT Arbor, said: \u201cEarlier this year, we released news of the trends we foresaw happening [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":24838,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4950,5,275,399,54,262],"tags":[8180,8181,561,8715,449,1053,563,390,8717,8179,8716],"class_list":["post-24837","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-enterprise-security","category-intelligent-technology-newsletter","category-more-news","category-research","category-used","tag-arbors-security-engineering-and-response-team","tag-asert","tag-bryan-hamman","tag-cve-2014-8361","tag-cybercriminals","tag-ddos","tag-distributed-denial-of-service","tag-iot","tag-jenx","tag-netscout-arbor","tag-satori"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/24837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=24837"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/24837\/revisions"}],"predecessor-version":[{"id":24850,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/24837\/revisions\/24850"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/24838"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=24837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=24837"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=24837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}