NextElection - Make it count!
India
English
0
  • Search

  • Updates
  • Topics
  • Featured
  • Leaders
  • Parties

AboutContactTermsPrivacy
    ⚡ Powered by MainCross
    Dim the Navigation panel when not in use
    NZ’s cyber security centre warns more attacks likely following stock market outages
    science & technologyArticle01 Sep, 2020
    Last edited: 01 Sep, 2020, 7:15 PM

    NZ’s cyber security centre warns more attacks likely following stock market outages

    This is particularly damaging for financial information sites such as a stock market. They have a legal duty to give equal access to different users.

    The Government Communications Security Bureau (GCSB) has issued a warning to all New Zealand businesses to be prepared for cyber attacks, following almost a week of daily attacks on the New Zealand stock exchange (NZX).

    The attacks have caused outages, sometimes for hours, of NZX’s public-facing website since Tuesday last week. This week, it continued trading under a new arrangement that allows it to post information to alternative platforms.

    The attacks are part of worldwide malicious cyber activity and the government will likely share information via Interpol and government-to-government links, including the intelligence alliance know as Five Eyes.

    Creating millions of bots

    The type of attack is known as a Distributed Denial of Service (DDoS). The attacker infects large numbers, often thousands or even millions, of computers with a virus that allows the attacker to instruct the infected computer - known as a “bot” - to send thousands of requests for data to the target.

    In effect, this means millions of attempts to access a website at the same time. The website being attacked can’t respond to each one quickly enough so either it simply stops responding or responds to some but not all data requests. Some people get the most up-to-date page and others don’t.

    This is particularly damaging for financial information sites such as a stock market. They have a legal duty to give equal access to different users. They would normally shut down and stop trading for a while rather than allow some people to get information before others.

    These attacks are not designed to steal data or do insider trading. They are generally set up to demand ransom from the victims, usually asking for thousands of dollars paid in bitcoin or another cryptocurrency which is effectively untraceable. Governments, terrorist organisations, political groups and even pranksters have also been known to use these attacks.

    DDoS software is available on the dark web but also not very difficult to write. In many cases the people owning the bots will not be aware anything strange is happening.

    The current attacks

    Multi-day attacks have been rare but are becoming more common. The size of these attacks, including how many bots are used and their capacity to send requests, has been increasing.

    Such multi-day attacks are potentially risky for the attackers as the defence team will be analysing the attacks, often using artificial intelligence tools, and should be able to respond more quickly to block illegitimate requests.

    The defence against such attacks is based on being able to cope with the large number of requests, either by moving the website to a cloud-based system that can increase capacity quickly, or identifying bot requests and filtering them out by setting up a “whitelist” of legitimate users and excluding others.

    This is normally done by firewalls at the level of each attacked entity, the internet service provider or, as in the case of New Zealand, at a country’s electronic border (for example, the Southern Cross trans-Pacific network of communications cables).

    If an attack is coming from inside New Zealand, security software on the bot computer can normally remove the infection with up-to-date anti-virus software. Internet service providers can also detect this activity and may warn users or disconnect the infected machine until it is cleaned. But in this case, the attacks are coming from outside New Zealand.

    The COVID-19 pandemic means millions of people are working from home around the world, outside their normal corporate security, often using the family computer. Some people may be less careful about downloading software, particularly on illegal streaming sites, and may be using free or unsecured wifi networks. This makes infecting computers to turn them into bots much easier.

    How to repond

    Assuming this is a criminal gang, financial institutes are an attractive target. They rely on availability of service and potentially have money to pay ransoms.

    In New Zealand, disaster management and recovery has tended to focus on responses to natural hazards rather than criminal activity. New Zealand does not have local cloud providers and expanding capacity is more difficult.

    Even if NZX won’t pay a ransom, this attack is “advertising” for the criminal gangs that may act as “subcontactors” to larger criminal organisations.

    The government’s aim will not be to catch the perpetrators in the short term but to share information on how to block the attacks. Normally the response is effective, but it can take some time to analyse details.

    At the same time, other attacks (for example phishing to steal data) may use the confusion caused by the DDoS attacks to target potential victims. Organisations should encourage people to update their security software and remain vigilant.

    In the future, as the internet of things (IoT) becomes more widespread, many billions of new devices will be connected to the internet. Security standards and forensic capability (storing data to analyse attacks) are not universal and there is a danger that these attacks will become more common and larger in scale.

    But defence is possible and both technical and policy approaches are getting better. Artificial intelligence tools for rapidly analysing attacks are the focus of research.

    Support for governments in vulnerable areas is also increasing to enforce international agreements, clarify local law and share information between network providers. For example, Macau recently introduced a much tougher cyber security law which seems to have been very effective.

    Featured image: This map shows the number of global attacks on August 15.

    Article by Dave Parry, Head of the Department of Computer Science, Auckland University of Technology . First published on The Conversation.

    The Conversation

    The Conversation

    @theconversation

    Want to be informed when this author publishes the next article?

    Save, embed, share, report
    0comments
    About this channel
    science & technology

    Science & technology

    New Zealand

    Concerns administration around and quality of research, science and technology.

    More from this channel

    Select between trending, latest and important content.
    Update09 Oct, 2020

    International researchers have quantified for the first time the influence of proglacial lakes on mountain glaciers

    “This study is also critical because the timing of ice retreat is often used to determine the synchrony or lack thereof of in climate events globally. Major inferences have been made about the roles of phenomena like oceanic circulation in affecting...

    The University of Canterbury

    Proglacial lakes are accelerating glacier ice loss

    Meltwater lakes that form at glacier margins cause ice to recede much further and faster compared to glaciers that terminate on land, according to a...
    Update07 Oct, 2020

    New Zealand Association of Scientists : Massey University Cuts a Third of Science

    New Zealand Association of Scientists President and University of Waikato Professor Troy Baisden says, “The scope of the cuts to Massey University’s science capability is beyond alarming.” “Up to 40% of taught papers and about a third of academic...
    Update28 Sep, 2020

    The microbiome could help explain wide variation in the antibacterial properties of mānuka honey.

    The microbiome—a complex community of bacteria—was surprisingly specific and consistent for mānuka leaves, even across distant geographical locations, suggesting that these bacteria may play important roles in how mānuka responds to stress and different environmental conditions.

    waikato

    New study into mānuka leaf surface could help maximise high-grade honey production

    University of Waikato researchers have found a unique group of microorganisms on the surface of mānuka leaves, which could help explain wide variation...
    Article15 Sep, 2020

    Novel Kiwi Technology Could Make Mars Attainable

    Robinson Research Institute, Victoria University of Wellington, is developing technology to revolutionise spacecraft propulsion, making it more efficient to propel rockets while in space.
    Opinion07 Sep, 2020

    Let Kiwi Kids Thrive

    The Outdoors Party supports a school curriculum that places children in the natural world and gives them an education that fosters a relationship with nature and their community. Thriving kids. Thriving NZ. Authorised by Jenn Haakma, Secretary, NZ Outdoors Party, 117 Allen Road, RD1 Broadlands, Reporoa
    Article05 Sep, 2020

    Scientists Raise Safety Concerns For Glyphosate-Resistant GE Foods

    The researchers found severe metabolic disturbances in both stacked (multiple transgene) and single transgene trait GM soybeans caused by exposure to a glyphosate-based herbicide.
    Update01 Sep, 2020

    "That’s what we rely on government for, to ensure that those who are most vulnerable are ok"

    The Citizens Advice Bureau has produced a report revealing huge numbers of people suffer from ‘digital exclusion’ – those who have limited or no access to, or won’t or can’t use, digital technology.

    Stuff

    The Detail: Kiwis are suffering from 'Digital Exclusion' | Stuff.co.nz

    The 2018 census revealed 10 per cent of New Zealanders - more than half a million people - don't have internet access.
    Article01 Sep, 2020

    NZ’s cyber security centre warns more attacks likely following stock market outages

    This is particularly damaging for financial information sites such as a stock market. They have a legal duty to give equal access to different users.
    Article30 Aug, 2020

    SpaceBase Releases Free Assessment Tool To Grow The Space Industry In New Zealand

    Enormous opportunities to leverage existing terrestrial industries, to create space products & services, to benefit the different NZ regional economies, while solving global challenges on Earth.
    Update26 Aug, 2020

    Unlocking the aesthetic potential of microfluidics, turning petite research aides into masterpieces

    Combining their expertise, the two formed a research collaboration looking at how to best preserve microfluidic chips for visualisation and permanent display. Rebecca was among the researchers on their international team, whose scientific paper discussing ‘Art-on-a-Chip’ was recently published in leading nanotechnology journal Small.

    The University of Canterbury

    Science on display: 'Art-on-a-Chip' | University of Canterbury

    Studying how tiny amounts of liquid move through precisely engineered soft plastic chips is an exciting new field for scientists, particularly when...
    Update22 Aug, 2020

    Airports are the biggest user of facial recognition technologies globally, and police second.

    In New Zealand, NEC said it had a "particularly close relationship" with police. This included supplying finger and palm print biometrics, though facial recognition was not mentioned in NEC's PR material. It has been reported police here are using US company Dataworks Plus to replace their old facial recognition system.

    RNZ

    Global facial recognition company working closely with NZ govt | RNZ News

    A major company at the centre of controversies over facial recognition technology in the US and UK is working closely with the New Zealand government.

    Select your country

    The NextElection network is fully customized to each country.

    Looks like you are in USA. Click on your country flag to proceed.

    India
    United States of America
    New Zealand