Home > Security News > Authorize.Net says it has 'learned' from attack
Security News:
EMAIL THIS

Authorize.Net says it has 'learned' from attack

By Bill Brenner, News Writer
27 Sep 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Authorize.Net will use lessons learned from last week's distributed denial-of-service attacks to harden its defenses, company officials said. But that's of little comfort to people like David Hoekje, president of PartsGuy.Com, an online heating and air conditioning parts dealer based in Traverse City, Mich.

This is his busy season, and being cut off from one of the Internet's biggest credit card processing services left him dead in the water for days. By Thursday morning, he said service had only been partially restored. "This is a week where I should have been able to do enough business to carry me through to spring," Hoekje said. "My sales are just gone."

He added, "This is the first time I've taken a hit like this, and what I've learned is that the network needs major infrastructural improvements. Having a server on the Web to conduct business is just a poor way to do things. There has to be some architectural changes so a service like this won't be so vulnerable in the future."

Glen Zimmerman is spokesman for Burlington, Mass.-based Lightbridge Inc., which purchased Authorize.Net in March. He said the company is working with the FBI and outside consultants to minimize disruptions to its customers, which number about 90,000. While the company is regaining control, he acknowledged intermittent attacks persist.

"We've minimized the impact of each attack and have quickly restored services," he said. "But we're still having some problems, and we ask our customers to bear with us while we continue to work on it." Zimmerman said the company has put together a capital improvements plan to make the network more ironclad against future attacks. He declined to go into further detail, saying he doesn't want potential attackers to know what they're planning.

Roy Banks, general manager of Authorize.Net, said security has always been a priority and that protection was in place. The problem is the attackers caught the company off guard with their methods. "We've invested heavily in defense, and we thought we were prepared," he said. "But the nature of this attack was something we had never experienced."

Banks said Authorize.Net has "learned a great deal" from the past week, and will incorporate those lessons into the next round of security upgrades. "The tactics of these people are evolving," he said. "Our security will evolve so we can stay ahead of them in the future."

Hoekje hopes so. "As far as my customers are concerned, when my site is down it only reflects on me," he said.

Tom Corn, vice president of business development for Cambridge, Mass.-based security firm Mazu Networks, said distributed denial-of-service attacks are particularly serious because they take more sophistication and coordination to pull off than typical outbreaks.

"You're dealing with multiple zombie machines that are targeting this one site," he said. "The fact that this is a DDoS against a financial institution is not a good sign for the future. These guys monitor their victims during the attack and adjust their tactics as the victims try to make their own adjustments. It's difficult to recover from something like that."

Information security experts have long worried about the rapid rise of financially motivated attacks. Zimmerman said FBI officials told him such attacks have picked up since June. Corn noted that since April, at least two other credit card sites have been attacked.

"The big lesson is this: If you rely on these big businesses, you have to ask them questions about how secure they are, not just what their rates are," Corn said.

Tags: Denial of Service (DoS) Attack PreventionEnterprise Data GovernancePCI Data Security StandardVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Denial of Service (DoS) Attack Prevention
VeriSign extends DDoS attack protection service
Conficker authors prepping for next stage, researcher says
Latest DDoS attacks extremely unsophisticated, experts say
DDoS attacks hit U.S., South Korean government websites
How to prevent a denial-of-service (DoS) attack
I'll be watching you: Wireless IPS
How to prevent DDoS attacks on websites
How to prevent network denial-of-service attacks
What are 'phlashing' attacks?
Could someone place a rootkit on an internal network through a router?
Denial of Service (DoS) Attack Prevention Research

Enterprise Data Governance
How to protect distributed information flows
Interpreting 'risk' in the Massachusetts data protection law
Creating an enterprise data protection framework
Analyst DLP study finds maturity, ranks top DLP vendors
Voltage, RSA spar over tokenization, data protection
Twitter gets condemned by CISOs at Forrester forum
PCI DSS compliance requirements: Ensuring data integrity
Trustwave acquires data loss prevention vendor Vericept
Data has become too distributed to secure, Forrester says
Cloud-based security services should start private

PCI Data Security Standard
PCI DSS compliance help: Using frameworks, technology to aid efforts
Chip and PIN adoption
Chip and PIN adoption serves lesson for U.S. payment industry
Heartland CIO is critical of First Data's credit card tokenization plan
Heartland CIO on end-to-end encryption, credit card tokenization
Heartland CIO on PCI, E3 project
Wireless network guidelines for PCI DSS compliance
Visa probes tokens, encryption for PCI card data protection
Feds push cybersecurity jobs, PCI DSS changes ahead.
Voltage, RSA spar over tokenization, data protection

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Electrohippies Collective  (SearchSecurity.com)
packet monkey  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts