Smurfing & Fraggling Attacks Continue
Despite the evolution of information technologies in general, and malware in particular, one type of attack has largely remained unaltered: Denial of service attacks. It is now eight years since the first appearance of two of the most popular types of denial of service attacks: Smurfing and fraggling.
Smurfing consists, in general terms, of a denial of service (DOS) attack against a computer by using a vulnerable network. It involves sending a message (broadcast) from the attacker’s computer to all computers in the vulnerable network, simulating the victim and requesting a reply. In this way, the victim computer is saturated by numerous messages from computers on the network.
Fraggling is an enhanced version of the above, with the attacker, again simulating the victim, requesting more information from computers on the network so the victim is even more saturated than in the previous case.
“These types of attacks compromise both the end victim as well as the intermediary network,” explained Luis Corrons, director of PandaLabs. “Today these kinds of attacks are somewhat outmoded, as they use techniques, such as broadcasting messages to the whole network, that a firewall, if configured correctly, will not allow. But the essence of the attack still remains.”
Nowadays, the most common means for launching denial of service attacks are networks of zombies. These are groups of computers that have been hijacked by types of malware, commonly known as bots, that can be controlled remotely by malicious users and perpetrate coordinated action, such as mass-mailing or denial of service attacks, or even more silent and unidentifiable operations, such as targeted attacks.
“The use of botnets is no more than an evolution of the networks of the zombies compromised in smurfing attacks,” said Corrons. “Of course botnets are unfortunately more multipurpose by nature. In any event, the best solution to neutralize these attacks in corporate networks is clear: Use of a perimeter firewall, able to filter the packets used in the attack before they reach workstations.”
McAfee, IT Matrix Offer Vulnerability Management
Frequently reported technical vulnerabilities and their expected adverse impact to networks are causing increasing concern among business managers and information security professionals. The challenge is not only knowing what vulnerabilities there are, but also in having a vulnerability management system that assists in identifying which vulnerability requires immediate attention and then tracking its status accordingly.
Realizing the market’s need for an efficient vulnerability management solution, IT Matrix joined resources with McAfee and has jointly conducted a seminar on the practicalities of vulnerability management. The seminar in Riyadh was attended by high-profile information security professionals from the Saudi government, finance and enterprise sectors.
According to Kenan Abou Lteif, McAfee territory manager, organizations face a storm of information about threats and vulnerabilities. Advisories from newsgroups and security sites, combined with data from firewalls and intrusion detection systems, create a nonstop flood of information that grows daily. The sheer volume of this threat data makes it nearly impossible to determine which threats are critical and which are less relevant.
“McAfee realized this upcoming tsunami of vulnerabilities and therefore the timely acquisition of Foundstone and R&D investment has brought about a unique world class vulnerability management system,” Abou Lteif said. “Mission-critical networks and systems must be given priority over less important areas of the infrastructure. When all threat and vulnerability data is treated equally, vital areas might not get the immediate attention they require while less crucial areas take up too much time.”
In 2004, McAfee bought Foundstone of Mission Viejo, California, a company that made software for detecting and managing software vulnerabilities. McAfee’s threat management technology based on Foundstone Enterprise’s tools enables network managers to:
• Rapidly discover and map the entire global network;
• Pinpoint and prioritize the most valuable information assets;
• Rigorously probe for vulnerabilities and determine risk;
• Provide threat intelligence alerts for quick response to fast-spreading attacks;
• Facilitate strategic protection of selected critical assets, according to business requirements, policies and rules;
• Assign, manage and validate remediation and;
• Track and measure progress, improvements and cost/benefits.
Foundstone Enterprise also enables organizations to measure and manage their compliance to industry standards such as Sarbanes-Oxley, FISMA, HIPAA, BS7799/ISO17799 and PCI. Flexibility and customization allows customers to modify their vulnerability management process to comply with these standards. Regulation specific templates facilitate continuing compliance monitoring and annual reporting.
Attendees at the seminar were not only familiarized with all the possibilities of enhanced vulnerability management with Foundstone Enterprise but they also participated in a live demonstration of the solution conducted by Shahzad Subhani, security services manager, IT Matrix. Subhani took the participants through the full cycle from identifying the IT components in a network by simple scanning and then demonstrating how the correlation of IT assets and multiple vulnerabilities works to empower the administrator to make the intelligent choices of prioritizing and managing vulnerability patching.
“Now, in Saudi Arabia, clients want to understand security solutions before they consider integrating such solutions into their networks,” said Mirza Asrar Baig, CEO of IT Matrix. “McAfee has a strong commitment to the region and a proven interest in educating the customer. We have been working with them for four years in this market. In our research to identify the most efficient vulnerability management system we were sold on Foundstone even prior to McAfee’s acquisition. There is no doubt that vulnerability management is a key area of concern for network managers in Saudi Arabia and Foundstone Enterprise is the right solution to tackle this issue.”

