IT Security

US source of hostile cyber

by Mark Rowe

Cyber attacks from US-based IP addresses have increased for a third consecutive year, making the US a major source of hostile cyber activity. That’s according to the NTT 2016 Global Threat Intelligence Report. The annual Report contains security threats gathered during 2015 from 8000 clients of the NTT Group security companies including Dimension Data, Solutionary, NTT Com Security, NTT R&D, and NTT Innovation Institute (NTTi3). This year’s data is based on 3.5 trillion security logs and 6.2 billion attacks. Data is also gathered from 24 Security Operations Centres and seven research and development centres of the NTT Group.

During 2013, about half, 49 per cent of cyber attacks on IP addresses originated from within the US, and that number increased to 56 per cent in 2014. In 2015, this number increased to 65 per cent across 217 countries that detected attacks.

Matthew Gyde, Dimension Data’s Group Executive – Security says: “The US serves as a major source of hostile activity, due to the ease of provisioning and low cost of US cloud hosting services. While the source IP address is based in the US, the actual attacker could be anywhere in the world. Because of the ease with which attackers can disguise their IP addresses, attack sources can often be more indicative of the country in which the target is located, or perhaps of where the attacker is able to compromise or lease servers, rather than where the attack actually originates. Because a significant number of the detected attacks target US organisations, so attackers often host such attacks locally in the same geographic region as their victims. This reduces the likelihood that they’ll experience potential geolocation blocking or alerting.”

Gyde points out that the data is derived from correlated log events identifying validated attacks that took place in 2015. China, which was the source of the second-largest number of attacks (9 per cent) in the 2014, accounted for only 4 per cent of attacks in 2015. Australia, which was in third place in 2014, dropped to eleventh spot (1 per cent) as a source of attacks in 2015. Meanwhile, the UK became the number one source of non-US based cyberattacks in 2015: the number of attacks from addresses based in the UK rose slightly from 3 per cent in 2014, to 5 per cent 2015, making the country the primary source of non US-based attacks.

The report includes:

– the retail sector experienced nearly three times more attacks as those in the financial sector which topped the list of cyberattacks in the 2015 report. In 2015, cyberattacks on the financial industry dropped to 14th position.

– similar to the retail sector, the hospitality, leisure, and entertainment sector also processed high volumes of sensitive information including credit card data. Transactions in the hospitality sector, which includes hotels and resorts, tend to be sizable, which can make those card numbers attractive to attackers.

– cybercriminals are adopting low-cost, highly available, and geographically strategic infrastructure to perpetrate malicious activities. This can be seen by the increase in US-sourced attacks using cloud infrastructure.

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing