Thursday, July 09, 2009

North Korea Attacks American and South Korea Networks. True or False?

Recent International news 'claims' that North Korea WITH the help of China has electronically attacked South Korea and American websites. I use the word 'claim' to raise caution that in fact the attacks may not have come from these countries and in fact may have come from other countries or terrorist groups making it appear that the attacks originated from North Korea.

Today hackers can spoof and proxy hop so that a trace back to them would appear they are located in one place but in fact located in another. This brings me back to the movie "Untraceable"where FBI agent Diane Lane is trying to find this killer but cannot trace back to where he is. So this news makes me suspicious as to True or False here.

My word of caution is just that. Never assume that the point of origin is where a trace route brings you. It might bring you to the other side of the world when in fact it could be your neighbor.

I have to believe these sites all have some form of network security, mostly again depending on firewalls or IDS. I would have hoped that since IPS has been around for almost 7 years that everyone would have deployed one. But then again, not all IPS vendors and coverage is alike. Some have excellent DDOS protection, others have great signatures for a specific threat type.

I would highly suggest that companies that are still on Firewalls or IDS systems strongly consider investigating and IPS. And those that already have an IPS, take a fresh look at the newer third generation IPS systems that have the strongest DDOS protection.

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home