3

Newly identified 'Black Storm' attack could wreak havoc on CSP networks

 2 years ago
source link: https://siliconangle.com/2021/09/28/newly-identified-black-storm-attack-wreak-havoc-csp-networks/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
Newly identified 'Black Storm' attack could wreak havoc on CSP networks
8801184428_a8d3f14755_c.jpg
SECURITY

A newly identified cybersecurity threat coined “Black Storm” could potentially wreak havoc on communications service provider networks, according to new research released today by distributed denial-of-service protection company Nexusguard Inc. 

In a typical DDoS amplification attack, those behind the attack rely on DNS servers or other similar open services to interrupt connectivity. Where a Black Storm attack becomes both interesting and scary: Those using the method can leverage any device connected to the internet.

According to researchers at Nexusguard, the volume from one Black Storm attack could terminate medium- to large-sized enterprises in a clean sweep and severely cripple a large-scale CSP network.

Hackers are said to be able to achieve Black Storm attacks more easily than amplification attacks and could quickly dominate the cyber world. Black Storm attacks could be manifested by hackers reflectively employing a so-called BlackNurse attack. BlackNurse attacks are a form of denial-of-service attacks based on internet control message protocol or ICMP flooding.

By generating spoofed user datagram protocol requests to devices connected to a CSP on closed UDP ports, a reflection of the ping replies return to the CSP network ping sources in BlackNurse attacks. In these circumstances, the devices respond with destination port unreachable responses. As more devices continue to respond to the spoofed internet protocol source, the volume of responses completely overwhelms the targeted CSP network and hence becomes a Black Storm Attack.

The researchers at Nexusguard are advising CSPs to perform regular vulnerability scanning, apply access control to routers and use deep learning-based detection methods. The deep learning approaches can assist CSPs in analyzing data quickly and accurately while overcoming the inefficiencies inherent in threshold or signature-based methods.

“The potential risk from impending Black Storm attacks could obliterate individual enterprises and have devastating consequences for communications service providers and completely saturate their networks,” said Juniman Kasman, chief technology officer for Nexusguard. “Networks targeted by these attacks need to apply deep learning intelligence in order to analyze traffic patterns and identify Black Storm attacks well before they can be exploited.”

Photo: Dan Newsom/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Show your support for our mission by joining our Cube Club and Cube Event Community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger and many more luminaries and experts.

Join Our Community 

Click here to join the free and open Startup Showcase event.

“TheCUBE is part of re:Invent, you know, you guys really are a part of the event and we really appreciate your coming here and I know people appreciate the content you create as well” – Andy Jassy

We really want to hear from you, and we’re looking forward to seeing you at the event and in theCUBE Club.

Click here to join the free and open Startup Showcase event.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK