It will be much harder this year for companies to deflect the rising onslaught of cyberattacks orchestrated to knock them off the Internet.
Hundreds of times each day, attackers use a technique called distributed denial of service, or DDoS, that involves coordinating home PCs to flood targeted Web sites with nuisance requests — to the point where no one else can access the site.
Most DDoS attacks get blocked or filtered. But the volume and sophistication of such attacks accelerated in 2010, a trend that looks to intensify in 2011. “The good guys are slightly ahead,” says Craig Labovitz, chief scientist at network security firm Arbor Networks. “But it’s not clear this equilibrium will continue.”
One major driver: More home PCs than ever have broadband connections capable of sending large streams of data to commercial Web sites. That’s made it easier for protest groups to rally like-minded cohorts to join in attacks.
In September, protesters used their home PCs to bombard the Motion Picture Association of America’s Web site, knocking it offline for 20 hours. The motive: payback for MPAA’s alleged efforts to shut down PirateBay.org, a popular site for downloading pirated music and movies.
Home PCs were behind the December attacks that disrupted the Web sites of PayPal, Visa, MasterCard and PostFinance, a Swiss bank. Protesters sought to punish them for cutting off services to the WikiLeaks whistle-blower site.
While such outages are temporary, “brand damage” can be lasting, says Danny McPherson, head of research at Internet infrastructure firm VeriSign. “Losing customer trust can translate into lost revenue,” he says. No industry estimates of such losses are available.
Another big driver: DDoS attacks that stem from cybergangs controlling networks of infected home PCs, called botnets, are becoming more elaborate. “As it stands today, any Web service can be taken down at any time,” says Gunter Ollmann,…