In Depth

A Health-Care Provider Solves a Denial-of-Service Mystery

After daring a security vendor to prove his product worked, one network engineer ends up with a global solution for a denial-of-service attack.

By Scott Berinato

October 01, 2006CSO

First, the firewalls just stopped responding. Then the network jammed up, and within hours, the

network engineer, whom we'll call Cam Smith, had all IT hands on deck, engineers from vendor

companies on the phone and frustrated execs on his back demanding updates. Maybe too regularly,

Smith recalls. "I wanted to tell them, When we have an update we'll give it to you, because a lot of times

when they were asking, there was nothing new to tell them. We were trying to focus on the problem."

p>

The problem would last three days, a virtual eternity for Smith's company, a midsize healthcare

company with a network of hospitals (and one that forbids Smith from using his name or his company

name in the press). Smith first characterizes the situation as "intermittent outages." When pressed,

though, as if being forced to think about something he'd rather forget, he finally confesses, "We were

down about 90 percent of the time. And we had poor quality of service when we were up. It was a

terrible time." (Patient care systems were not affected, Smith says, in part due to backup systems. "But

they very easily could have been," he adds.)

Smith's company is a "tweener," a midsize company, bordering on big, and probably big enough to

consider forming a dedicated information security team. But so far, the company still folds security into

the IT department. Smith is part of an ad hoc security committee made up of network engineers with

enough security experience to handle incidents.

It was on the third day of the crisis that the team discovered the DoS attack, in which a high

volume of legitimate but useless traffic floods a network and crashes it. "We could tell it was coming

from somewhere inside our network, but we couldn't tell from where," he says. So Smith and company

moved through the server room literally pulling plugs, one network zone at a time, to isolate the zone

letting in all the DoS traffic.

This went on for about three hours, Smith says, until finally the team located the source of the

attack: a single remote user on a dial-up connection, working from home on a company laptop, halfway

across the country.

Smith called the employee and told her to disconnect the machine, and the network came back.

Crisis over. Forensics commence. With the laptop shipped back to headquarters, Smith and his team

scrubbed it and found links to a malicious website that used ActiveX to take over the computer and

launch the DoS attack. The employee had downloaded a toolbar she had used at her previous job. What

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage

Configuration Assessment: Choosing the Right Solution

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Digital Identity Protection and Data Security Get Personal

The Case for Business Software Assurance ~ Securing Your Applications

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era