Skip the navigation

An Imaginary DoS Attack Uncovered

A complaint from a competitor is a diversion from our security manager's strategic objectives for the year. Mathias Thurman

By Mathias Thurman
November 21, 2005 12:00 PM ET

Computerworld - The other day, our CIO forwarded me an e-mail from our general counsel's office, saying that one of our competitors was accusing us of what amounts to a directed denial-of-service attack.
The complaint was that we were making excessive requests to the competitor's public Web site, hitting its performance so hard that customers were unable to access it. The IP address involved in this attack did indeed belong to us; I recognized it as one of our proxy addresses. You see, all outbound connections made from inside our company are translated to a single public IP address controlled by our proxy servers.
My first thought was that someone had been spoofing our IP address, but first I had to check to see if any of our internal resources were responsible for any of the suspicious activity. In order to do that, I simply had one of my engineers search through the logs of our proxy server for the destination IP address.
Search Results
Surprisingly, the search led to the identification of a single IP address within our company. The dates and times matched up almost to the second with the logs provided by our competitor's network administrators. It was obvious now that one of our employees had been making connections to our competitor's Web site.
Next, we used the NBTSTAT utility within Windows to enumerate the machine name and the media access control (MAC) address. These are two important pieces of information in the incident-response process. Machine names in our company are set to the employee's log-on name, a method that usually makes it easy to identify which resource belongs to whom.
The MAC address is useful because I can have one of our network engineers search the switches' CAM (content addressable memory) tables for the MAC address. That would tell us the switch port involved, and we could then trace back to the office jack where the PC that was involved is attached.
In addition to identifying the employee tied to this IP address, we put a filter on our intrusion-detection system to watch for connections he made. What we observed seemed to be an automated connection from his desktop to the competitor's site every hour. After some discussion with our legal department and human resources, I ended up giving this guy a call.
Turns out his job is conducting competitive analysis. He uses a tool that lets him monitor all of our competitors' Web sites for changes to content. So, for example, if one of our competitors launched



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs