Showing posts with label DDOS. Show all posts
Showing posts with label DDOS. Show all posts

Tuesday, June 13, 2017

NTIA Attempting to Address Botnet Issues

Today the Department of Commerce’s National Telecommunications and Information Administration (NTIA) published a request for public comment (RFC) in the Federal Register (82 FR 27042-27044) requesting comments on actions that can be taken to address automated and distributed threats to the digital ecosystem. This request is part of the activity directed by the President in Executive Order 13800 (EO 13800).

NTIA is looking for comments on attack mitigation and endpoint prevention strategies to address distributed denial of services (DDOS) attacks that use botnets. NTIA is looking for specific comments on the topics below and any additional insights that might be available. The specific topics include:

Gaps in existing approaches;
• Potential methods of addressing the problem;
Role of the Federal government;
International nature of the problem; and
User prevention activities.


NTIA is soliciting public comments. Comments may be sent by email (counter_botnet_RFC@ntia.doc.gov). Comments should be submitted by July 13th, 2017.

Thursday, October 27, 2016

ICS-CERT Publishes Honeywell Advisory and ICS DDOS Warning

Today the DHS ICS-CERT published a control system security advisory for the Honeywell Process Knowledge System (PKS). They also issued a warning about the potential for distributed denial of service (DDOS) attacks on internet facing industrial control system products.

Honeywell Advisory


This advisory describes an improper input validation vulnerability in the Honeywell Experion Process Knowledge System (PKS) platform. This is apparently a self-reported vulnerability. Honeywell has produced patches to mitigate the vulnerability.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to prevent the Experion PKS client tools from uploading firmware to Series-C devices.

ICS DDOS Warning


ICS-CERT posted a very short and very generic warning about the potential for DDOS attacks on internet facing control systems or components thereof. This is based upon the US-CERT report about recent very large DDOS attacks. There is no information provided that indicates a specific threat against ICS.

ICSJWG Spring Meeting



ICS-CERT recently published a notice concerning the date of the 2017 Spring meeting of the ICSJWG in Minneapolis, MN over April 11th thru 13th, 2017.
 
/* Use this with templates/template-twocol.html */