All the latest UK technology news, reviews and analysis

Hackers' Stick beats detection tools

by James Middleton

16 Mar 2001

Be the first to comment

  • Tweet this

Malicious coders have developed an attack tool that can perform a denial of service attack against many popular intrusion detection products.

The tool, known as Stick, directs thousands of overt attacks at security systems, causing them to fall over.

Coretez Giovanni, of US-based security company Endeavor Systems, told vnunet.com that flaws in the implementation and development of IDS software were one of the main reasons for the success of these tools.

"Stick succeeds because script kiddies are operating security. People are downloading and buying IDS without knowing what or why," he said.

"On the development side IDS must be able to validate that the alarm is correct. This means that the IDS needs to determine if the pre-cursor and post events that occurred confirm or deny that an attack is real," he added.

Security firm Internet Security Systems said Stick uses "very straightforward techniques" of firing numerous attacks from random IP addresses to purposely trigger IDS events. As the IDS system attempts to keep up with the flood of events it puts more strain on the system, eventually resulting in denial of service.

As the Stick attack works on a 'flooding' level, its effectiveness is limited by the bandwidth available to the attacker, although this also means attackers with more bandwidth at their disposal will be more successful.

ISS has developed two fixes for RealSecure Network Sensor, one of the most popular IDS products, which are available here.

A white paper on Stick is available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

28%

1%

13%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Software Developer (.Net, VB.Net) – Skipton

Graduate Developer / Software Developer (.Net, VB.Net...

PHP Developer / Web Developer (PHP4/5, Object Orientated PHP)

PHP Developer / Web Developer (PHP4/5, Object Orientated...

Web Games Designer

Web Games Designer – Gibraltar Web Games Designer...

E-commerce Business / Systems Analyst - retail

An exciting opportunity for a Systems / Business Analyst...

To send to more than one email address, simply separate each address with a comma.