Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. "The barriers to entry in that marketplace are so low you have people basically flooding the market," said Jose Nazario, a security researcher with Arbor Networks. "The way you differentiate yourself is on price."
Criminals have got better at hacking into unsuspecting computers and linking them together into so-called botnet networks, which can then be centrally controlled. Botnets are used to send spam, steal passwords, and sometimes to launch DDoS attacks, which flood victims' servers with unwanted information. Often these networks are rented out as a kind of criminal software-as-a-service to third parties, who are typically recruited in online discussion boards.
DDoS attacks have been used to censor critics, take down rivals, wipe out online competitors and even extort money from legitimate businesses. Earlier this year a highly publicised DDoS attack targeted US and South Korean servers, knocking a number of websites offline.
Are botnet operators having to cut costs like other businesses in these troubled economic times? Security researchers don't know if that's been a factor, but they do say that the supply of infected machines has been growing. In 2008, Symantec's internet sensors counted an average of 75,158 active bot-infected computers per day, a 31 percent jump from the previous year.
DDoS attacks may have cost hundreds or even thousands of dollars per day a few years ago, but in recent months researchers have seen them going for bargain-basement prices.
Nazario has seen DDoS attacks offered in the $100-per-day range, but according to SecureWorks Security Researcher Kevin Stevens, prices have dropped to $30 to $50 on some Russian forums.
And DDoS attacks aren't the only thing getting cheaper. Stevens says the cost of stolen credit card numbers and other kinds of identity information has dropped too. "Prices are dropping on almost everything," he said.
While $100 per day might cover a garden-variety 100MB/second to 400MB/second attack, it might also procure something much weaker, depending on the seller. "There's a lot of crap out there where you don't really know what you're getting," said Zulfikar Ramzan, a technical director with Symantec Security Response. "Even though we are seeing some lower prices, it doesn't mean that you're going to get the same quality of goods."
In general, prices for access to botnet computers have dropped dramatically since 2007, he said. But with the influx of generic and often untrustworthy services, players at the high end can now charge more, Ramzan said.
Cut-price botnets pose growing security threat
A one-day DDoS attack now costs £20
By Robert McMillan | 15 October 09
-
1:
Samsung Galaxy S4 vs Apple iPhone 5 comparison review
-
2:
Best cases and covers for the new iPad: protect your tablet in style
-
3:
What’s the best mobile OS: iOS, Android, Windows Phone 8 or BlackBerry 10?
-
4:
How to set a song on your iPhone as a ringtone
-
5:
Apple iWatch release date and specs: when will Apple's iWatch launch
-
1:
Samsung Galaxy S4 vs Apple iPhone 5 comparison review
-
2:
Galaxy S4 vs BlackBerry Z10 comparison review - which is best, the Samsung or the BlackBerry?
-
3:
Surface Pro review - Microsoft tablet offers true power computing on the move
-
4:
Samsung Galaxy S4 vs Google Galaxy S4 comparison review
-
5:
Apple iPad Mini vs Google Nexus 7 vs Samsung Galaxy Note 8.0 comparison review
Latest Videos
Samsung Galaxy S4 video review
Samsung is back with a new flagship Android smartphone. The Galaxy S4 is here to take on the heavyweights including Apple, HTC and Sony. Here's our Samsung Galaxy S4 video review.
Latest Reviews
-
Samsung Galaxy S4 vs Google Galaxy S4 comparison review
Want to know what the difference is between the Samsung Galaxy S4 and the Google Galaxy S4? Read…
-
Samsung Galaxy S4 vs Apple iPhone 5 comparison review
Samsung and Apple smartphones going toe to toe. Find out whhich is better in our Galaxy S4 vs…
-
Canon EOS 100D review: tiny digital entry-level SLR camera
This tiny digital SLR may be small, but it competes with much larger cameras. Read our Canon EOS…
Latest How-To
-
How to add bookmarks to home screen in Android
Create a shortcut to your favourite websites on your Android smartphone or tablet
-
9 social media mistakes your business must avoid
One errant or rogue post can derail your business's reputation. Learn what not to do from these real-world cautionary tales.
-
8 essential features you need in a business router
It's not enough to offer the latest wireless standard. Make sure the router that will support your office is up to snuff.





Comments