Le Lézard
Classified in: Science and technology
Subject: SVY

Q4 2017 Akamai State of The Internet / Security Report Shows Botnets Shift Focus to Credential Abuse


CAMBRIDGE, Mass., Feb. 20, 2018 /PRNewswire/ -- Newly released data that analyzed more than 7.3 trillion bot requests per month found a sharp increase in the threat of credential abuse, with more than 40 percent of login attempts being malicious, according to the Fourth Quarter, 2017 State of the Internet / Security Report released by Akamai Technologies, Inc. (NASDAQ: AKAM). According to the Ponemon Institute, credential stuffing attacks can cost businesses as much as $2.7 million on an annual basis. In addition, Akamai's data further indicates that DDoS attacks remain a consistent threat and the Mirai botnet is still capable of strong bursts of activity.

Akamai Technologies logo. (PRNewsFoto/AKAMAI TECHNOLOGIES)

Akamai researchers have seen recent hacker activity turning to exploit remote code execution vulnerabilities in enterprise-level software to make enterprise systems part of the botnet threat. For example, hackers have been exploiting vulnerabilities in the GoAhead embedded HTTP server?which has 700,000 potential targets?and Oracle WebLogic Server. Aided by the disclosure of Spectre and Meltdown earlier this year, both vulnerabilities open the door to a new wave of attacks, including the surreptitious installation of crypto mining programs that tie up computing resources.

"A key motive of attackers has always been financial profit. In the past few years, we have seen adversaries move to more direct methods to achieve that goal such as ransomware," said Martin McKeay, senior security advocate and senior editor, State of the Internet / Security Report. "Crypto mining offers attackers the most direct avenue to monetize efforts by putting money immediately into their cryptowallets."

Akamai's findings also confirmed that the total number of DDoS attacks last quarter (Q4 2017) increased 14 percent from the same time last year (Q4 2016). While previous reports from this year showed the intensity of the Mirai botnet fading, Akamai saw a spike of nearly 1 million unique IP addresses from the botnet scanning the Internet in late November, showing that it is still capable of explosive growth.

By the Numbers:

Other highlights from Akamai's Fourth Quarter, 2017 State of the Internet / Security Report include:

Bot Activity Drives Rising Threat of Credential Stuffing

On a typical day, Akamai monitors more than 2,750 bot requests per second, which accounts for more than 30 percent of all pure web traffic (excluding video streaming) across its platform. While much of that bot activity is legitimate, cybercriminals are increasingly leveraging bot activity for malicious use. For example, many of the botnets traditionally responsible for DDoS attacks are being used to abuse stolen login credentials. Of the 17 billion login requests tracked through the Akamai platform in November and December, almost half (43 percent) were used for credential abuse.

"Increased automation and data mining have caused a massive flood of bot traffic to impact websites and Internet services. Although most of that traffic is useful for Internet businesses, cybercriminals are looking to manipulate the powerful volume of bots for nefarious gains," said McKeay. "Enterprises need to watch who is accessing their sites to differentiate actual humans from both legitimate and malicious bots. Not all web traffic and not all bots are created equal."

A complimentary copy of the Q4 2017 State of the Internet / Security Report is available for download at akamai.com/stateoftheinternet-security. Learn more about the cost of credential stuffing by registering for a webinar with Dr. Larry Ponemon, founder of Ponemon Institute, on Wednesday, February 28, 2018.

Methodology
The Akamai Fourth Quarter, 2017 State of the Internet / Security Report combines attack data from across Akamai's global infrastructure and represents the research of a diverse set of teams throughout the company. The report provides analysis of the current cloud security and threat landscape, as well as insight into attack trends using data gathered from the Akamai Intelligent Platform. The contributors to the State of the Internet / Security Report include security professionals from across Akamai, including the Security Intelligence Response Team (SIRT), the Threat Research Unit, Information Security, and the Custom Analytics group.

About Akamai
As the world's largest and most trusted cloud delivery platform, Akamai makes it easier for its customers to provide the best and most secure digital experiences on any device, anytime, anywhere. Akamai's massively distributed platform is unparalleled in scale with over 200,000 servers across 130 countries, giving customers superior performance and threat protection. Akamai's portfolio of web and mobile performance, cloud security, enterprise access, and video delivery solutions are supported by exceptional customer service and 24/7 monitoring. To learn why the top financial institutions, e-commerce leaders, media & entertainment providers, and government organizations trust Akamai please visit www.akamai.com, blogs.akamai.com, or @Akamai on Twitter.

Contacts:


Tim Whitman

Tom Barth

Media Relations

Investor Relations

617-444-3019

617-274-7130

[email protected] 

[email protected]

   

SOURCE Akamai Technologies, Inc.


These press releases may also interest you

at 07:35
IonQ , a leader in the quantum computing industry, announced today the appointment of Peter Chapman as its next Chairman of the Board and Harry You as the Lead Independent Director of the Board, effective at the close of IonQ's upcoming Annual...

at 07:35
Arrowhead Pharmaceuticals, Inc. today announced its plan to host a 2024 Summer Series of R&D webinars that highlight multiple clinical stage RNA interference (RNAi) based medicines that utilize the company's proprietary Targeted RNAi Molecule...

at 07:25
Are you fully prepared to complete your BEAD State Challenge Process? If not, your path to success just got easier. The Sanborn Map Company's (Sanborn) Broadband Navigatortm is now available on the NASPO ValuePoint cooperative purchasing program...

at 07:21
Lynk & Co captivated visitors at the Beijing Auto Show with its EM-P, a plug-in hybrid electric vehicle (PHEV) powertrain based on the Lynk E-Motive platform. The EM-P, showcased in models such as the 06EM-P, 07EM-P, 08EM-P, and 09EM-P, garnered...

at 07:18
In a significant move to facilitate seamless payment experiences for international attendees, the 135th China Import and Export Fair ("Canton Fair" or "the Fair") has partnered with multiple financial institutions to upgrade its payment systems. This...

at 07:09
Hitachi Ltd. (TSE: 6501, "Hitachi") has signed a stock purchase agreement on April 26 to acquire all shares of MA micro automation GmbH ("MA micro automation", headquartered in St. Leon-Rot, Germany) from MAX Management GmbH (a subsidiary of MAX...



News published on and distributed by: