Verisign Q4 2014 DDoS Trends: Public Sector Experiences Largest Increase in DDoS Attacks

Verisign just released our Q4 2014 DDoS Trends Report, which provides a unique view into online distributed denial of service (DDoS) attack trends from mitigations on behalf of, and in cooperation with, customers of Verisign DDoS Protection Services, and the security research of iDefense Security Intelligence Services. Many notable observations were made, including a rise in the average size of DDoS attacks against our customers; the most common attack vector continued to be User Datagram Protocol (UDP) amplification attacks leveraging Network Time Protocol (NTP), while Simple Service Discovery Protocol (SSDP) also continued to be exploited. Verisign also mitigated more attacks in December than any other month in 2014.

The most notable observation, however, is that public-sector customers experienced the largest increase in attacks, constituting 15 percent of total mitigations in Q4. Verisign believes the steep increase in the number of DDoS attacks levied at the public sector may be attributed to attackers’ increased use of DDoS attacks as tactics for politically motivated activism, or hacktivism, against various international governing organizations, as well as in reaction to various well-publicized events throughout the quarter, including protests in Hong Kong and Ferguson, Missouri. As outlined in iDefense’s 2015 Cyber Threats and Trends blog post, the convergence of online and physical protest movements contributed to the increased use of DDoS as a tactic against organizations, including the public sector, throughout 2014.

(more…)

Help Ensure the Availability and Security of Your Enterprise DNS with Verisign Recursive DNS

At Verisign, we’ve made the Domain Name System (DNS) our business for more than 17 years. We support the availability of critical Internet infrastructure like .com and .net top-level domains (TLDs) and the A and J Internet Root Servers, and we provide critical Managed DNS services that ensure the availability of externally facing websites to customers around the world.

As we continue to expand our role in Internet security, we are excited to announce the next step in protecting the stability of enterprise DNS ecosystems: Verisign Recursive DNS. This new cloud-based recursive DNS service leverages Verisign’s global, securely managed DNS infrastructure to offer the performance, reliability and security that enterprises demand when securing their internal networks and that communications safely and securely reach their intended destinations.

(more…)

Internet Grows to 284 Million Domain Names in the Third Quarter of 2014

Today, we released the latest issue of the Domain Name Industry Brief, which showed that the Internet grew by four million domain names in the third quarter of 2014. The total number of domain names across all top-level domains (TLDs) is now 284 million. This is a 1.6 percent increase over the second quarter of 2014. [1]

Largest TLDs by Zone Size

TLD by Zone Size Q3 2014
Source: Zooknic, Q3 2014; Verisign, Q3 2014; Centralized Zone Data Service, Q3 2014

(more…)

Where Do Old Protocols Go To Die?

In Ripley Scott’s classic 1982 science fiction film Blade Runner, replicant Roy Batty (portrayed by Rutger Hauer) delivers this soliloquy:

“I’ve…seen things you people wouldn’t believe…Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate. All those…moments…will be lost in time, like (cough) tears…in…rain. Time…to die.”

The WHOIS protocol was first published as RFC 812 in March 1982 – almost 33 years ago. It was designed for use in a simpler time when the community of Internet users was much smaller. WHOIS eventually became the default registration data directory for the Domain Name System (DNS). As interest in domain names and the DNS has grown over time, attempts have been made to add new features to WHOIS. None of these attempts have been successful, and to this day we struggle with trying to make WHOIS do things it was never designed to do.

(more…)

Verisign OpenHybrid™: An Essential New Approach to DDoS Protection

Distributed Denial of Service (DDoS) attacks are a threat to businesses worldwide and the attacks are getting larger and more sophisticated.  The industry’s approach to protecting against DDoS attacks must change, and change fundamentally, to stay ahead of this growing threat.

For too long, the problem has been tackled piecemeal, using isolated devices or services. But protecting against DDoS attacks increasingly requires communication and coordination between many components – from networking equipment, to specialized appliances and cloud-based services.

A shift in security architecture is needed to an open platform where devices and services from different vendors can share and act on information in concert. It must be a hybrid platform, allowing on-premise routers and security appliances to detect and mitigate attacks locally, while automating alerting and switchover to cloud-based services if an attack threatens to swamp the business’ network connection.

(more…)

What’s Really New in the New gTLD Space?

As someone who has long studied trends in the domain name industry, the opening of hundreds of new gTLDs has intrigued me for quite some time on many levels. One question I found myself pondering was: Will new gTLDs create “new” naming trends or redundant domains across many TLDs? With more than 3 million domains delegated in the new TLD space there is now a corpus to study to answer this question.

The short answer is clear from these first two pie charts which illustrate the percentage of the second-level domains (SLDs) that were available in .com as of 12/15/2014:

(more…)

New from Verisign Labs: What’s in your attack surface?

Recently, Verisign Labs researcher Eric Osterweil and Verisign CSO Danny McPherson, along with Lixia Zhang, a professor of computer science at UCLA, received the Best Paper Award at this year’s IEEE Workshop on Secure Network Protocols (NPSec ‘14) for their paper, “The Shape and Size of Threats: Defining a Networked System’s Attack Surface.” Below is a guest post from one of the authors, Eric Osterweil, principal researcher for Verisign Labs, describing the genesis of the research and future plans.

(more…)

Domain Registrations: Is Bitcoin Going Mainstream?

Earlier this year we used Bitcoin as an example of how domain registrations could be an effective gauge of interest in a particular subject. Our analysis demonstrated a clear rise in the number of registered .com and .net domain names containing the term “Bitcoin” in 2013, as well as a positive correlation between increased registration activity and increases in the dollar value of bitcoin.

In this post, we decided to take a look at the history of Bitcoin-related domain registration activity since 2009 to see if we noticed any other trends.

(more…)