Rice University logo
Top blue bar image
A graduate seminar: current topics in computer security

Distributed denial of service attacks as a commercial service

Earlier in the semester, this paper we presented proposed that the botmasters running Torpig operated it as a commercial service. While DDoS was probably only a small subset of the services Torpig’s botmasters offered, this article at TechWeekEurope looks into the whos and whys of commercial DDoS services. It has a couple pictures of advertisements offering DDoS to links of some ridiculous YouTube advertisements, both which are hilarious in a ‘I’m still in high school and think I am the 1337est ever’ sort of way. Most of the evidence feels anecdotal, but it seems likely enough.

So what kinds of people run botnet DDoS services? One interviewed DDoS provider claimed to be 17 and a computer science student, and his behavior (taking down a 1337 hax00r forum for thirty seconds to prove who he was) certainly makes him sound like he’s still in high school. The other interviewees were more careful about just who they were, though, so more professional criminals appear to offer these services as well.

Targets vary. Anonymous protests are often on the news, but ‘hacktivists’ aren’t the only DDoS customers. Gwapo’s DDoS services advertises that “rivals, haters, they are to go down” and “If you want your business competitors to go down”, you should hire them, indicating that individuals want to DDoS smaller websites for petty personal attacks or to take out a business competitor. DDoS dealers can also hold online businesses for ransom – pay up or get taken down. Therefore, just about anyone with an online presence could be a target.


One Response to “Distributed denial of service attacks as a commercial service”

  1. on1 says:

    And not surprisingly, 40 million DDoS attack attempts have been detected last year by Kaspersky security lab last year. It gives us a good notion why DDoS attacks are not merely attacks anymore. In fact it is really fascinating to find out DDoS attacks have become a business for hackers and companies spend money on attacking the competitors. In the report by Kaspersky, security system against network attacks stated HTTP flood attacks which seem a simple kind of attacks consist 80% of all DDoS and DDoS is the third most common attack in the last year.

Leave a Reply

You must be logged in to post a comment.