IP Reputation Report-07012019

July 4, 2019 | Adeline Zhang

Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at June 30, 2019. Top 10 countries in attack percentage: First place changed from Laos to Suriname. The Palestine is in the second place. The country China (CN) has […]

Botnet Trend Report-3

July 3, 2019 | Adeline Zhang

This chapter discusses various aspects of botnet behavior. Behavioral characteristics include activity level of botnets overall and per botnet family, DDoS attack characteristics, C&C server use and distribution, and geographical locations of attack victims.  Also discussed are characteristics of the most active botnet families themselves.

DDoS in the Past Decade

July 1, 2019 | Adeline Zhang

1.0   Milestones 1.1   DDoS Size Expansion IP data source: The Zettabyte Era: Trends and Analysis The past decade has witnessed a steady growth in the peak size of DDoS attacks, especially in 2013 when the reflection method was used by attackers on a large scale and the DDoS attack size expanded at an exponential rate. […]

What You Should Know About Mitigation Bypass

June 28, 2019 | Adeline Zhang

Mitigation measures are implemented with many implicit assumptions. They can work only when these assumptions prove to be true and would be bypassed if these assumptions were broken.

IP Reputation Report-06242019

June 27, 2019 | Adeline Zhang

1. Top 10 countries in attack counts: The above diagram shows the top 10 regions with the most malicious IP addresses from the NSFOCUS IP Reputation databases at June 21, 2019.   Top 10 countries in attack percentage: The Laos is in the first place since four weeks ago. The Suriname is in the second […]

Botnet Trend Report-2

June 26, 2019 | Adeline Zhang

Botnets have evolved since 2017.  New active families and platforms have become dominant.  Attack types used have also changed.

Linux Kernel Multiple Remote Denial-of-Service Vulnerabilities Threat Alert

June 25, 2019 | Adeline Zhang

Overview Recently, Red Hat released a security bulletin, pointing out multiple TCP-based remote denial-of-service vulnerabilities in the Linux kernel, namely, a SACK Panic vulnerability of important severity and two other vulnerabilities of moderate severity.

TP-Link Wi-Fi Extenders Remote Code Execution Vulnerability (CVE-2019-7406) Threat Alert

June 24, 2019 | Adeline Zhang

Overview Recently, a security expert from IBM X-Force discovered a remote code execution vulnerability (CVE-2019-7406) in multiple models of TP-Link Wi-Fi extenders. This vulnerability can be exploited by unauthenticated, remote attackers by sending a malformed HTTP request so as to execute arbitrary shell commands on a target Wi-Fi extender. The attack does not require escalation […]

Apache Axis Remote Code Execution 0-Day Vulnerability Handling Guide

June 21, 2019 | Adeline Zhang

Vulnerability Overview Recently, by using the Attack Trend Monitoring system (ATM), the NSFOCUS security team has discovered an Apache Axis remote command execution vulnerability, which allows attackers to obtain privileges of the target server and remotely execute commands without authorization by sending a crafted HTTP-POST request.

IP Reputation Report-06172019

June 20, 2019 | Adeline Zhang

1. Top 10 countries in attack counts:

Search

Subscribe to the NSFOCUS Blog