NAB floats denial-of-service threats to the cloud

Thanks to bots and the rise of financially-driven cybercrime, the menace of distributed denial-of-service (DDoS) attacks has spurred collaboration between ISPs and telcos to push security to the cloud.

A year on from the DDoS attack that hit NAB, general manager for technology, security and risk at the bank, Gary Blair, said it is still investigating the crime.

"In terms of the actual event itself, the incident is still under investigation. These are necessarily long term and the information needs to be correlated with other similar attacks that have taken place prior and since," Blair told ZDNet Australia.

While the number of DDoS attacks against financial institutions, government departments and online businesses such as gambling and porn sites has increased in recent years, so too has the scale of attacks. Increased broadband penetration and the prevalence of bots is adding power to the arsenal of cybercriminals bent on disrupting services, which in some cases, is used as leverage to blackmail businesses.

Want to know more?

For all the latest news, analysis and opinion on security, click here

Although thousands of DDoS attacks are launched daily, according to Sean Lord, consultant for Verizon's IT services division, roughly four percent are conducted by professional crime groups.

"We saw a number of online betting organisations on the day before the Melbourne Cup receiving blackmail threats but its one thing to be able to hear about it from gambling sites because they're not as worried about risk to their reputation, versus banks, which are petrified they would lose their institutional online customer base. An even larger dimension to this is the Estonian DDoS attacks, which were politically motivated and country specific," said Lord.

Although NAB's Blair said the bank was well prepared for the attack it experienced, DDoS still disrupted services, prompted NAB to warn customers of new phishing threats and forced the bank to review its defence capabilities against DDoS attacks.

"Coming out of it, we took the opportunity to review what we could do differently. We concluded that we did perform well, but there are things we have done with our telco partners which mean that we have the ability to prevent these types of attacks further up in the cloud, so to speak," said Blair.

The call for ISPs and telcos to provide "clean pipes" is not new but has remained elusive for the general public. For larger organisations however, which want control over packet traffic volumes, rather than malware or pornography, telcos are offering security services to "shape" and "scrub" incoming traffic to prevent DDoS attacks.

"One of the key things was recognising that the defence-in-depth principal doesn't start at the perimeter -- it extends to the cloud -- and that as we do so, we need to work closely with our telco partners to shape and manage the traffic," said Blair. Defence in depth represents the multi-layered approach to security to help minimise the effects of a single layer being compromised.

Although, for security reasons, Blair was unwilling to divulge the methods the NAB or its telco partner uses to prevent DDoS attacks, he said it "ensures that we effectively receive clean traffic to our perimeter".

Verizon's Lord said that telcos -- Telstra, Optus, Singtel, AT&T, Verizon and BT included -- all use the same basic architecture for these services, with the main differentiator being that AT&T and Verizon have the most wide coverage of the world's networks.

Scrubbing and shaping
Two key techniques used to defend against DDoS attacks in the cloud are shaping and scrubbing packet traffic.

"Shaping, for me, suggests that I will make a haphazard analysis of total volume and I would reduce it on the basis of a desired volume. Scrubbing is the establishment of a white-list profile of good packets and then, through behavioural and holistic analysis, a recognition of what constitutes good versus bad packets and the removal of the bad packets," said Lord.

However, cloud security present a different challenge to Australia's local telcos such as Telstra and Optus compared to their larger multinational peers, Lord said.

"I would suggest a differentiator for a global tier one telco is that they can do that at a regional rather than a country basis. [Local telcos] have to 'throw away' at the borders of Australia whereas Verizon can 'throw away' at the borders of Asia," said Lord.

A network that many local telcos are "queuing up for" but are yet to join, said Lord, is Arbor Network's Fingerprint Sharing Alliance.

The Fingerprint Sharing Alliance is being touted by Arbor Networks as a method by which telcos and ISPs can share threat information without revealing competitive information.

"This is the beginning of cross ISP intelligence gathering," said Lord, who reckons the intelligence gathered from such a network is the essential ingredient to true security in the cloud. One major benefit of such an approach, he added, is that it allows telcos to recognise the origins of a bad packet and trace it back to its source.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

Mobile Devices Were Wrecking My Health. Here's How I Plan to Change That. - ZDNet (blog) http://t.co/zMWCOZOr #mobiledevices

"take up of the highest plan was again higher in April, making up 50 per cent of all services activated in April"

49 minutes ago by Abel Adamski on NBN users opt for 100Mbps

What has not been considered which may well be the case, is the key attribute of the FTTP. Upload capability. 82% chose an upload capacit...

54 minutes ago by Abel Adamski on NBN users opt for 100Mbps

"@ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/PiR0zeF1 #infosec #hack #cybersecurity"

Cool: NZ will host part of Square Km Array http://t.co/a2mz3DC5. Sad: @smh couldn't bring themselves to acknowledge it http://t.co/l90oLuYp

Build your own smartphone stand http://t.co/I0avWsRO

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/vA11Otks

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/FqSe1Uju

SKA bid ends in three-way tie AU/NZ/ZA http://t.co/aGw6dndH < interesting outcome

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

Is #PR dying at the hands of #SocialMedia? Check out how #UnitedAirlines suffered a Social PR hiccup in 2008 http://t.co/OVpYX8Uv

The interface is nowhere near as clean and user friendly as the Rdio streaming service apps. It doesn't compete with Rdio which has very ...

2 hours ago by Jeff12345 on Spotify finally goes live in Australia

RT @ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/0rCoszCl #infosec #hack #cybersecurity

by http://t.co/vmlLt4bh: SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the ... http://t.co/ySDRbo3l

It's official. The SKA bid has ended in a three-way tie between Australia, South Africa and New Zealand: http://t.co/Wn1niauX ^LH

Biometric bugs too dangerous for public?
http://t.co/48XQpWiY

Aussies getting ripped off by retail: Choice http://t.co/6ZQ0wuCJ via @zdnetaustralia

Thats really interesting to find this post especially in this period of my life I'm Italian, I'm owner of a website that ships worldwide...

3 hours ago by salbini on Aussies getting ripped off by retail: Choice

Android's biggest security flaws - ZDNET - ZDNet Australia http://t.co/4j4R1x6Q

RT @Techmeme: RIP webOS: Again and for good this time (@jkendrick / ZDNet) http://t.co/RhADp6WL http://t.co/fFYGIy5R

Cybercrime golden age over in two years? http://t.co/LyqqjWYU #Cybercrime #Gescrise #Riskmanagement (via @ECCOUNCIL)

RT: ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/X0In9ijs #infosec #hack #cybersecurity

Cybercrime golden age over in two years? http://t.co/VJnt6nEo #infosec #hack #cybersecurity

NBN users opt for 100Mbps - http://t.co/C2Vs7d3t

Yes, if only he had access to FTTP instead of wishing for wireless or space optics, perhaps the comedy site would still be up and running...

4 hours ago by Beta on NBN users opt for 100Mbps

I could not resist :-)

I remember that website well, you must too, it was full of so many comedy pieces.

4 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

Bazaarvoice acquires rival PowerReviews; adds SMBs to CRM portfolio: By Andrew Nusca | May 25, 2012, 4:42am PDT ... http://t.co/WngvcsxL

MikeSkoey, what a naive collection of words. How do you know what context Paul has been working in. How do you know he implemented whats ...

4 hours ago by AnonymousCIO on 30 servers to 7: BUPA redoes virtualisation

Post 'social' improved speed to information and context http://t.co/7u9odG7N

HC, don't be so mean to Todd...

He is actually one who may not be just politically opposed ;-)

4 hours ago by Beta on NBN users opt for 100Mbps

No, Quigley is, as CEO's of all companies are, quite simply motivated for his company to be a professional and successful company, as it ...

5 hours ago by Beta on NBN users opt for 100Mbps

Forced lol. btw I tried to load your website www.nonbn.org but all I got was a "website unavailable" I really wanted to donate some mone...

5 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

http://t.co/aDIOqQ4c http://t.co/NeUOcLt5

What has the debt level got to do with what plan people chose? I'd point out that the debt wont be $50 billion but i'd be wasting my bre...

5 hours ago by mstat_z on NBN users opt for 100Mbps

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

6 hours ago by merarischroeder on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

6 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

6 hours ago by gikku on Triple J's Spotify conundrum

NBN users opt for 100Mbps - Communications - News http://t.co/3A84AASP

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

6 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

6 hours ago by Beta on NBN users opt for 100Mbps

HC the critics said the NBN wouldn't make a cent (yes, yes here comes the, it's still in debt arguments - we know what you meant and so d...

6 hours ago by Beta on NBN users opt for 100Mbps

Look what you did Gwyn...LOL. Yes, but as you have been told umpteen times Mathew (whenever you sprout the same old repetitive lines abo...

6 hours ago by Beta on NBN users opt for 100Mbps

It's great that in one area NBNCo are beating the prediction on speed tiers in the Corporate Plan (page 118). Unfortunately it is the onl...

6 hours ago by mathew42 on NBN users opt for 100Mbps

10 cool iPad apps you'll wish you found sooner | 2 of 10 http://t.co/M9SXbnJS via @zite

Do you have a reference for the 40% in Willunga? The only public figures I've seen are 29% for Willunga and 26% for Kiama. It would cert...

7 hours ago by mathew42 on NBN users opt for 100Mbps

SA Health's journey to ehealth Business News ZDNet Australia: Implementing e-health services for an entire state... http://t.co/QuiOy7OQ

London to become Intel's city-living R&D testbed - ZDNet UK (blog): IT PROLondon to become Intel's city-living R... http://t.co/5qdivDa1

#Google #Australia Much ado about Google's tax http://t.co/DCMsJGyN

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

by http://t.co/vmlLt4bh: Build your own smartphone stand: Looking for a smartphone stand, but not interested in d... http://t.co/DptVvkoB

Build your own smartphone stand: Looking for a smartphone stand, but not interested in dishing out the dough? We... http://t.co/TgSeZIdM

last couple of hours to submit your application for #crmidol. Step up and take your chance! http://t.co/7vQxdbY3 #scrm #crm #value

The rural Silicon Valley http://t.co/vqV6bl5i

Build your own smartphone stand http://t.co/IY6VxA7n

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar