OpKillingBay 2016


November 9, 2016 02:00 PM

Network and application attacks against countries and organizations involved in whale and dolphin hunting has become an integral part of hunting season.

Download a Copy Now

Background

Online protests in the form of network and application attacks against countries and organizations involved in whale and dolphin hunting has become an integral part of hunting season. OpKillingBay is an annual Advanced Persistent Denial of Service attack (APDoS attack) campaign created by Anonymous. During the hunting season, which runs from September to March, street protests are accompanied by online protests in the shape of largescale cyber-attacks (See Figure 1).

While the main target for OpKillingBay is Japan, parallel Anonymous operations target European countries such as Denmark, Faroe Islands, Iceland, and Norway. The attackers launch network and application floods to disrupt the operation of those involved in hunting, such as government institutions and large corporations (see Target List below). Last year, hackers took down the websites of the Tokyo Narita International Airport and the car manufacturer Nissan with similar APDoS attacks.

 


Figure 1: Tweets from OpKillingBay 2016

Reasons for Concern

Radware expects denial of service attacks, data dumps and service outages caused by OpKillingBay. Attackers are using tools like Nmap designed for network discovery and security auditing. They are also using basic script tools used to launch Layer 7 attacks in combination with stresser services. As part of their target lists, OpKillingBay attackers will identify ports to attack and if the target has DDoS mitigation solutions implemented.

Advanced Persistent Denial of Service Attacks (APDoS Attacks)

These APDoS attacks are hard to avoid, as the core of the issue is an ideological difference. While victims of these attacks are conducting business within their rights, the group behind OpKillingBay and other operations are driven by emotions and what they believe to be social injustice. As these two groups continue to disagree, we expect to see a persistent state of attacks. These attacks can be labelled as APDoS attacks due to their multi-vector attacks and the length in which the attacks can last. These campaigns usually begin with port scanning attempts to launch various attacks at different volumes and durations with the goal of identifying weaknesses and blind spots.

Industries Targeted

  • Transportation
  • Retail
  • Banks
  • 政府
  • Media
  • Tourism
  • Union Workers
  • Academics
  • Automotive
 

Targets 1

#EndTaiji Targets

  • http://www.pref.wakayama.lg.jp
  • http://www.dolphinbase.co.jp
  • http://www.dolphinresort.jp
  • http://tokyo2020.jp
  • http://www.waza.org
  • http://www.maff.go.jp
  • http://www.imata.org
  • http://icrwhale.org
  • http://www.rakuten.co.jp
  • http://town.taiji.lg.jp
  • http://marineworld.hiyoriyama.co.jp
  • http://pearlsea.jp
  • http://beachland.jp
  • http://www.kamogawa-seaworld.jp
  • http://ioworld.jp
  • http://www.new-yashima-aq.com
  • http://nixe.co.jp
  • http://oki-park.jp
  • http://www.notoaqua.jp
  • http://otaru-aq.jp
  • http://nagoyaaqua.jp
  • http://www.marinepia.or.jp
  • http://shimoda-aquarium.com
  • https://www.umitamago.jp
  • http://www.seaparadise.co.jp
  • http://sumasui.jp
 

#FreeFins Targets

  • http://www.loroparque.com
  • http://www.zoo-duisburg.de
  • http://tiergarten.nuernberg.de
  • http://www.kolmarden.com
  • http://www.dolfinarium.nl
  • https://www.atticapark.com
  • http://www.boudewijnseapark.be
  • http://www.zoobarcelona.cat
  • http://www.marineland.fr
  • http://www.planetesauvage.com
  • http://www.antalyadolphinarium.com
  • http://www.selwomarina.es
  • http://ranchotexaslanzarote.com
  • http://www.parcasterix.fr
  • http://www.acquariodigenova.it
  • http://www.leonimarinirimini.it
  • http://www.oltremare.org
  • http://www.istanbuldolphinarium.com

Follow on Twitter

Hashtags

  • OpKillingBay
  • OpKillingBay EU
  • EndTaiji
  • FreeFins
  • FreeFinsEU


Figure 2: Touch My Tweets targets Japanese website

Scanning Tools For OpKillingBay

Nmap – Nmap is a security scanner designed for network discovery and security auditing. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering. In addition, they identify what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics.

Attack Vectors For OpKillingBay

Layer 7 (HTTP) Flood - HTTP flood consists of seemingly legitimate session-based sets of HTTP GET or POST requests sent to a target Web server. These requests are specifically designed to consume a significant amount of the server’s resources, and therefore can result in a denial-of-service.

HTTP makes it difficult for network security devices to distinguish between legitimate HTTP traffic and malicious HTTP traffic, and could cause a high number of false-positive detections. Rate-based detection engines are also not successful at detecting HTTP flood attacks, as the traffic volume of HTTP floods may be under detection thresholds. Because of this, it is necessary to use several parameters detection including rate-based and rate-invariant.

SQL Injection – This technique takes advantage of poor application coding. When the application inputs are not sanitized it becomes vulnerable. Attackers can modify an application SQL query to gain access to unauthorized data with administrator access, run remote commands on the server, drop or create objects in the database and more.

Organizations Facing APDoS Attacks Should Consider

  • Hybrid DDoS Protection (on-premise + cloud) – for real time protection that also addresses high volume attacks and protects from pipe saturation.
  • Behavioral-Based Detection - to quickly and accurately identify and block anomalies while allowing legitimate traffic through.
  • Real-Time Signature Creation - to promptly protect from unknown threats and zero-day attacks.
  • A cyber-security emergency response plan that includes a dedicated emergency team of experts.

In addition, we recommend that you review your network patch your system according. Maintaining and inspecting your network often is necessary in order to defend against these types of risks and threats.

Under Attack and in Need of Expert Emergency Assistance? Radware Can Help.

Radware offers a DDoS service to help respond to security emergencies, neutralize the risk and better safeguard operations before irreparable damages occur. If you’re under a DDoS attack or malware outbreak and in need of emergency DDoS attack prevention, Contact us with the code "Red Button".

 

1https://ghostbin.com/paste/5h8gm

 

Click here to download a copy of the ERT Threat Alert.

立即下载

与Radware销售部门接洽

我们的专家将回答您的问题、评估您的需求,并帮助您了解哪些产品最适合您的业务。

已经是客户?

无论您需要支持或更多服务,还是需要解答有关我们产品和解决方案的问题,我们都会随时提供帮助。

公司地点
马上从知识库获得答案
获得免费在线产品培训
联系Radware技术支持部
加入Radware客户计划

参与社交

联系专家并加入有关Radware技术的对话。

Blog
安全研究中心
CyberPedia