{"id":42313,"date":"2017-07-13T04:00:00","date_gmt":"2017-07-13T08:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/ciras-joint-webinar-nominum-underlines-extent-growing-cybercrime-threat-2\/"},"modified":"2023-03-10T10:57:29","modified_gmt":"2023-03-10T15:57:29","slug":"ciras-joint-webinar-nominum-underlines-extent-growing-cybercrime-threat-2","status":"publish","type":"cira_news","link":"https:\/\/stg-saas.cira.ca\/fr\/ressources\/nouvelles\/cybersecurity-fr\/ciras-joint-webinar-nominum-underlines-extent-growing-cybercrime-threat-2\/","title":{"rendered":"CIRA&#8217;s Joint webinar with Nominum underlines extent of growing cybercrime threat"},"content":{"rendered":"<p>Yuriy Yuzifovich\u00a0recently joined CIRA&#8217;s Mark Gaudet for a webinar to discuss some of the key trends and findings contained in Nominum&#8217;s Spring 2017 <em>Data Revelations<\/em> report.<\/p>\n<p><!--more--><\/p>\n<p>Public awareness of cybercrime and its impact is at an all-time high\u00a0as businesses and individuals alike deal with new waves of ever-more sophisticated malware attacks. Phishing scams, DDoS, IoT and ransomware attacks \u2013 all are making their presence felt in new and increasingly disruptive ways.<\/p>\n<p>According to an extensive new <a href=\"https:\/\/nominum.com\/wp-content\/uploads\/2017\/04\/nominum-spring-2017-data-science-security-report.pdf\">study<\/a> from Nominum, a CIRA partner and global leader in DNS-based security, cybercrime has reached unprecedented \u2013 and alarming \u2013 new levels in 2017.\u00a0<\/p>\n<p>Nominum&#8217;s head of data science and security research, Yuriy Yuzifovich, recently joined CIRA&#8217;s Mark Gaudet for a CIRA-sponsored webinar to discuss some of the key trends and findings contained in Nominum&#8217;s Spring 2017 \u201cData Revelations\u201d report. The report is the culmination of an in-depth analysis of the state of the cyber security landscape conducted by Yuriy and his data science team over the previous six months.<\/p>\n<p>As Yuriy explains during the webinar, Nominum is uniquely positioned to conduct this type of analysis on the rapidly evolving domain of cybercrime. It has access to a vast data store of DNS queries \u2013 its servers process upwards of 100 billion DNS queries every day \u2013 and it continues to improve its DNS-based security algorithms so it can detect and neutralize new threats as quickly and effectively as possible.\u00a0<\/p>\n<h2>Malicious queries are growing exponentially<\/h2>\n<p>Among the key findings outlined by Yuriy in the webinar is the rapid increase in malware queries seen over the first several months of 2017. As part of its research, Nominum conducted a comprehensive analysis of 15 trillion DNS queries to uncover domains hosting any form of malware, along with any DNS queries being made to these domains.\u00a0<\/p>\n<p>Its analysis revealed that the number of queries to malicious domains is growing exponentially. In fact, the average number of malicious queries per day increased by 404% over the previous twelve months.<\/p>\n<p>During the month of February 2017, the median number of malicious queries per day was 101 million. The highest number of malicious queries measured during a single day, also recorded in February, was 217 million. By contrast, in the six-month period covered by Nominum&#8217;s Fall 2016 Data Revelations report, there was not a single day during which 100 million or more queries to malicious domains were recorded.\u00a0<\/p>\n<figure>\n<div class=\"media media-element-container media-default\"><img loading=\"lazy\" decoding=\"async\" alt=\"The number of malicious queries per day has grown from a median of 19 million per day in Q3 2016 to 101 million per day in Q2 2017\" title=\"Malicious queries per day\" height=\"365\" width=\"600\" class=\"media-element file-default\" src=\"https:\/\/static.cira.ca\/sites\/default\/files\/public\/Nomimum-daily-queries.png\" \/><\/div><figcaption>\n<p>In Q2 2017 median malicious queries grew to an all time high of 101 million per day<\/p>\n<\/figcaption><\/figure>\n<p>While the number of queries to malicious domains is increasing, the number of new malicious domains is likewise growing, in part owing to the use of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Domain_generation_algorithm\">domain generation algorithms (DGA)<\/a> by hackers. During the reporting period, monthly growth in the number of new domains hosting malware was 18%.<\/p>\n<p>As Yuriy points out in the webinar, Nominum&#8217;s data scientists attribute the growth in malicious domains and queries to several factors. The number of new threats is steadily growing as more and more hackers and cybercriminals continue to introduce new bots and malware at regular intervals; the commercialization of malware (such as the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Locky\">Locky<\/a> strain of ransomware) is making it easier than ever before for hackers to launch successful attacks with minimal effort; and cybersecurity experts like Nominum are continuing to refine and improve the tools and methods they use to detect new types of malware.<\/p>\n<h2>Ransomware, Phishing, and PRSD attacks also on the rise<\/h2>\n<p>Growth in malicious domains and queries, is only part of the story. Nominum also reports a significant upsurge in other types of cyberattacks, including ransomware attacks, phishing scams, and PRSD attacks.\u00a0<\/p>\n<p>The first of these, ransomware attacks, grew 270% since the release of Nominum&#8217;s Fall 2016 report. This notable increase aligns with another important finding highlighted in the webinar: the largest proportion of all malware threats \u2013 28 percent \u2013 are now motivated by financial theft, of which ransomware is the leading variety.\u00a0<\/p>\n<figure>\n<div class=\"media media-element-container media-default\"><img loading=\"lazy\" decoding=\"async\" alt=\"Types of attacks from various vectors showing financial theft at 27%, mobile root at 7%, spam at 5%, backdoor at 16%, DDoS at 9%, file corruption at 16% and various others at 12%\" title=\"Types of attacks and their target\" height=\"570\" width=\"600\" class=\"media-element file-default\" src=\"https:\/\/static.cira.ca\/sites\/default\/files\/public\/nominum-top-threats-function.png\" \/><\/div><figcaption>\n<p>Types of attacks showing financial theft (including ransomware) being the leading reason at 28% of all types<\/p>\n<\/figcaption><\/figure>\n<p>Nominum&#8217;s research also indicates significant growth in another form of DNS-related attack. Pseudo Random Subdomain, or PRSD attacks, are a form of DDoS attack in which an attacker floods the DNS server with requests for multiple non-existent domains. The incidence of these types of attacks increased 68% in the first three months of 2017 over the previous three-month period.\u00a0<\/p>\n<h2>Conclusion &#8211; threats are growing and so to should defence in depth strategies<\/h2>\n<p>These are some of the key highlights from our joint webinar with Nominum, all of which point to a future where cyber threats continue to grow and evolve, giving hackers the weapons to launch increasingly effective attacks over time. These findings should also prompt businesses to re-examine their defenses against cybercrime to avoid potentially catastrophic consequences.\u00a0<\/p>\n<p>If you would like a personalized webinar for your team, you can <a href=\"https:\/\/calendly.com\/cira\/dnsthreats\">book a meeting with us here<\/a>. To learn more about the findings from Nominum&#8217;s Spring 2017 Data Revelations report, you can <a href=\"https:\/\/nominum.com\/resource\/security-report-nn\/\">view the report in its entirety online<\/a>.\u00a0<\/p>\n<p>If you are looking to learn how CIRA&#8217;s D-Zone <a href=\"https:\/\/acei.ca\/enterprise-products\/d-zone-anycast-dns\">Anycast<\/a> and <a href=\"https:\/\/acei.ca\/d-zone-dns-firewall\">Firewall<\/a> solutions can help your business avoid falling prey to the growing list of new cyber threats, <a href=\"https:\/\/calendly.com\/cira\/dnsthreats\">please contact us today<\/a>. \u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yuriy Yuzifovich\u00a0recently joined CIRA&#8217;s Mark Gaudet for a webinar to discuss some of the key trends and findings contained in Nominum&#8217;s Spring 2017 Data Revelations report.<\/p>\n","protected":false},"featured_media":2735,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"CIRA's Joint webinar with Nominum underlines extent of growing cybercrime threat - CIRA","description":"Yuriy Yuzifovich\u00a0recently joined CIRA's Mark Gaudet for a webinar to discuss some of the key trends and findings contained in Nominum's Spring 2017 Data Revelat"},"footnotes":""},"topic":[1066],"class_list":["post-42313","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blogue","cira_topic-cira-topic-cybersecurity-fr","cira_author-robwilliamson-fr"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42313\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/wp\/v2\/media\/2735"}],"wp:attachment":[{"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/wp\/v2\/media?parent=42313"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/fr\/wp-json\/cira\/v1\/topic?post=42313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}