In case you don't read any of what I have to say below, read this: I have dual citizenship. Along with my homeland citizenship, I am of the Internet, and see it as my personal duty to try and make the Internet safe.
Atrivo (also known as Intercage), is a network known to host criminal activity for many years, is no more.
Not being sarcastic for once, this is time for some self reflection.
I wish I was one of those who sleep soundly tonight. Being clear in my conviction that Atrivo should be out of business, and being positive my decision to help that happen was sound--While I would do it again, I am sad.
I won't sleep soundly tonight, as that company, criminal and abusive as it clearly and contemptuously was, still sustained quite a few families in several layers of employment, from sysadmins sitting in the US of A all the way to minor low-level fraudsters employed by their clients' clients.
I will however, be able to look myself in the mirror for my part in the
effort to get rid of them--and even gloat some. My conscious is as clear to me as my sadness is crystal. We may not have changed the wall of battle in the long term and whenever one criminal falls, another jumps up to the opportunities of the land of the free--the Internet. But for once, just for a while, we halted the machine. We stopped the wheels of evil, even if only for a fortnight.
While doing so, ee also touched some lives in a destructive fashion. The criminals'.
No villain ever sees himself as the bad guy, as the saying goes. A friend recently showed me Russian language comments written on Brian Krebs' recent Washington Post story. In them, the posters ask: "why do you take our bread away?"
In a lecture during ISOI 5, some folks just didn't understand the meaning. Their bread. Their bread. We in the Western world, behind the cultural divide speak a different language. Their culture isn't poorer than ours, it is unequivocally different.
We can not truly comprehend what it means for some folks in Russia to no longer be able to feed their children this month. Nor can we understand that by sending email, we made those children starve. Cheap theatrics on my part, you say? You got that right. It doesn't make it any less true.
Cyber crime is a war waged against the Western world. At first, no one even noticed and it was a niche.. an art. While the artists still exist, they are a minority, the hackers. For the criminals however, motive is as irrelevant as nationality. Whatever actions are taken, be it a political defacement, fraud or spam, the unavoidable secondary impact remains the same: damage to the Western economy and security in an exponential growth which will become ever clearer in the coming years.
Yes, my friends. I would do the same again. I feel sorry for Atrivo, but they were harboring the equivalent for the Internet of active missile launchers firing on Israel from the Gaza strip. They are human beings who hit a curve in the road to their success. Cyber criminals, however, establish such growth as parasites and whatever I may feel for needing to resort to the end game weaponry, these people need to be smacked down like cockroaches.
Ten years ago they were a pride to their parents, today they are a scourge. What will they be in ten years?
If all reasonable and even some unreasonable approaches fail. That does not mean I don't have to feel sorry for them, and me. But it also doesn't mean we don't need to fight back.
Not even a hundred years ago, disastrously, war was business and an
acceptable horrifying part of life. A few years later, in 1918, war was
unthinkable. In the century since we who live in or are influenced by
Western culture made war no longer an option we can publicly stomach, while facing those who would play us like children because of it.
War is horrifying and evil, it is also a last resort in a world not as
ascendant as we would like to think. The Internet has its own "liberals" and I am proud to be one of them. However, I am also practical and see that wishing for a world we once had is not. A world where I could host files on my neighbor's servers openly, where children could happily use pocket calculators and go to libraries for their school work rather than Google and read Wikipedia. You did so, do your children?
This new world has its price, and that price is a complete loss of public privacy, and a culture of ineffective security.
We are reliant on our Auntie Jane's computer knowledge for our own security, and while not many would follow us to our bathrooms to infringe on our personal privacy, online we have no privacy, however much it helps us to lie to ourselves that something we do publicly (read, on the Internet) is private.
I accepted that, but that is because I am in the trenches for years. Others live better not knowing. But it doesn't mean I won't work diligently to make it remain.. functional.
Indeed, taking a step back from my niche in security, and seeing how bad things truly are--people can still surf for porn, and argue over who the best Star Trek captain is. Cyber crime, in all its immense activity of billions of incidents an hour, is background noise. But the background noise continually increases. When will it overflow?
All I really want is to maintain the functionality we have, regardless of the abuse. And yet... Going back to Atrivo, they made enough money by now. And regardless once more, their criminal clients are already back online elsewhere--in some places possibly hosted by what seems like Atrivo, only under a different name.
We did not win, but boy does it feel good to have a victory once in a while for morale's sake. We halted the machine, even if only just for a short time. That, my friends, also has strategic implications as far as our ability is to influence networks running clean on the Internet, although only time will determine if I am right on that.
Enough whining though. Who is next on the target list? :)
More seriously, why do I care so much? I have dual citizenship. Along with my homeland citizenship, I am of the Internet, and see it as my personal duty to try and make the Internet safe.
Gadi Evron,
Of the Internet.
ge@linuxbox.org
Follow me on twitter! http://twitter.com/gadievron
Showing posts with label atrivo. Show all posts
Showing posts with label atrivo. Show all posts
Sunday, October 05, 2008
Thursday, September 25, 2008
Internet Vigilantism
The good people at Renesys wrote a blog about what they call "Internet Vigilantism".
While I feel I can not yet fully comment on the whole Atrivo / Intercage depeering movement, there is an underlying strategy to consider. I will comment at a later date.
The blog above asks:
There is a difference between Vigilantism as it is perceived today and Vigilantism as it is in the dictionary. It means neighborhood watch.
When the Police is not around, that is something you need. "It's for the children".
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
While I feel I can not yet fully comment on the whole Atrivo / Intercage depeering movement, there is an underlying strategy to consider. I will comment at a later date.
The blog above asks:
While I'm not a big fan of cyber-crime or the providers who knowingly host these activities, I can't help but wonder where law enforcement is in this story. We still have laws, right? There is a lot of questionable activity and content on the Internet that is thriving and has no shortage of suitors. Even the most cursory look of of what passes for "content" should convince anyone that it's pretty hard to get thrown off the Internet — it just doesn't happen. But since it just did, I have no trouble believing that Atrivo had it coming. It's tough to piss off the entire world, especially when you have the money to pay them off. I only wonder why the cops didn't get there first [...]My response is, 'okay', but please don't call it Vigilantism.
There is a difference between Vigilantism as it is perceived today and Vigilantism as it is in the dictionary. It means neighborhood watch.
When the Police is not around, that is something you need. "It's for the children".
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Labels:
atrivo,
neighborhood watch,
strategy,
vigilantism
Saturday, September 06, 2008
Cyber crime: an economic problem
During ISOI 4 (hosted by Yahoo! in Sunnyvale, California) whenever someone made mention of RBN (the notoriously malicious and illegal bulletproof hosting operation, the Russian Business Network) folks would immediately point out that an operation just as bad was just "next door" (40 miles down the road?), working undisturbed for years. They spoke of Atrivo (also known as Intercage). The American RBN, if you like.
In fact, while many spam operations use botnets and operate all around the world, a lot of the big players own their own network space and operate hosting farms, which are constant and "legitimate", right in the US--for years now.
While we may not be able to make contact and mitigate incidents in some countries, these operations inside the United States of America run undisturbed. They register thousands of domain names every day and fuel a whole economy, starting with spam continuing with phishing, malware and DDoS attacks, and ending in child pornography and more spam.
Background
For years the Internet has become increasingly "dirty". It isn't just about the thousands and millions of concurrent security incidents (automated, malicious code-based and other) happening every minute of every day.
It isn't even about the next stage, the botnets and massive fraud attacks. It's about the problem not changing. The Bad Guys (TM) or miscreants as some of us tend to call them (I prefer criminals) are a business. They have R&D, operations, outsourcing and so on. They collect statistics to make sure their revenue stream is maintained, and act to rectify the situation if it isn't.
They (ab)use the Internet for their business, but have shown, in old Russian war style, that if you go against them, they are not afraid of destroying this reveue stream called the Internet. Scortched Earth is an acceptable strategy. The criminals established a working deterrence on the Internet, as unlike us, they are willing and capable of using their power, to let the Internet go (root server attacks, Blue Security incident, etc.).
To change this equation the first realization we had was that this is an economic problem.
Changing the Economic equation
To impact their business you have to change how they treat it. This comes down to a basic cost vs. benefit calculation:
Anecdote: some UK banks lose over a million POUNDS each every DAY during phishing and banking malware attack waves.
We used to be able to impact their cost by "killing" their botnets, or making sure phishing sites stayed "on the air" for less time.
They have contingencies, design and operations to ensure they are never "down". They register domains for use just for a few minutes, and then discard them. Their botnets immediately jump to a new location if one "goes down", if it wasn't just a temporary location to begin with.
Graceful degradation is terminology not reserved just for the house of representatives.
This is not always true. When "bullet proof" hosting is found, they don't need to jump around. Example, some phishing sites hosted on Atrivo's IP space have been up and running since early 2007.
By taking down malicious sites, or as we like to call it, whack-a-mole (it just pops up somewhere else) we played the game, and they got better at what they did--they evolved.
The answer was: law enforcement. If the RISK factor became high enough, we could change the economics of the problem space.
Unfortunately, while having good intentions and good people, law enforcement is:
Law enforcement vs. maintaining our networks
At some point every network operators comes to this fork in the road. "Do I maintain my network and kick this SOB off my network, or wait for law enforcement?"
The answer should be self-evident by now, best intentions included.
This ties back in to the current situation with Atrivo / Intercage, which we will discuss later.
Gadi Evron.
Follow me on twitter! http://twitter.com/gadievron
In fact, while many spam operations use botnets and operate all around the world, a lot of the big players own their own network space and operate hosting farms, which are constant and "legitimate", right in the US--for years now.
While we may not be able to make contact and mitigate incidents in some countries, these operations inside the United States of America run undisturbed. They register thousands of domain names every day and fuel a whole economy, starting with spam continuing with phishing, malware and DDoS attacks, and ending in child pornography and more spam.
Background
For years the Internet has become increasingly "dirty". It isn't just about the thousands and millions of concurrent security incidents (automated, malicious code-based and other) happening every minute of every day.
It isn't even about the next stage, the botnets and massive fraud attacks. It's about the problem not changing. The Bad Guys (TM) or miscreants as some of us tend to call them (I prefer criminals) are a business. They have R&D, operations, outsourcing and so on. They collect statistics to make sure their revenue stream is maintained, and act to rectify the situation if it isn't.
They (ab)use the Internet for their business, but have shown, in old Russian war style, that if you go against them, they are not afraid of destroying this reveue stream called the Internet. Scortched Earth is an acceptable strategy. The criminals established a working deterrence on the Internet, as unlike us, they are willing and capable of using their power, to let the Internet go (root server attacks, Blue Security incident, etc.).
To change this equation the first realization we had was that this is an economic problem.
Changing the Economic equation
To impact their business you have to change how they treat it. This comes down to a basic cost vs. benefit calculation:
- Cost (earning less or spending more)
- Benefit (earning more or losing less)
Anecdote: some UK banks lose over a million POUNDS each every DAY during phishing and banking malware attack waves.
We used to be able to impact their cost by "killing" their botnets, or making sure phishing sites stayed "on the air" for less time.
They have contingencies, design and operations to ensure they are never "down". They register domains for use just for a few minutes, and then discard them. Their botnets immediately jump to a new location if one "goes down", if it wasn't just a temporary location to begin with.
Graceful degradation is terminology not reserved just for the house of representatives.
This is not always true. When "bullet proof" hosting is found, they don't need to jump around. Example, some phishing sites hosted on Atrivo's IP space have been up and running since early 2007.
By taking down malicious sites, or as we like to call it, whack-a-mole (it just pops up somewhere else) we played the game, and they got better at what they did--they evolved.
The answer was: law enforcement. If the RISK factor became high enough, we could change the economics of the problem space.
Unfortunately, while having good intentions and good people, law enforcement is:
- Considerably under-staffed
- Hardly able to communicate inside the US
- Barely able to communicate with agencies in other countries
- When able to communicate, it often takes up to a year (unless they go off the books and talk to the folks directly rather than through Interpol)
- When successful, often takes years (more than two) to build a case
- Then, success is rare in comparison to the number of incidents
Law enforcement vs. maintaining our networks
At some point every network operators comes to this fork in the road. "Do I maintain my network and kick this SOB off my network, or wait for law enforcement?"
The answer should be self-evident by now, best intentions included.
This ties back in to the current situation with Atrivo / Intercage, which we will discuss later.
Gadi Evron.
Follow me on twitter! http://twitter.com/gadievron
Saturday, August 30, 2008
GBLX pulled link to Atrivo/Intercage
It seems like GBLX is no longer peering with Atrivo/Intercage.
Who is next?
My original post on this:
http://gadievron.blogspot.com/2008/08/washington-post-atrivointercage-why-are.html
Gadi Evron,
ge@linuxbox.org
Follow me on twitter! http://twitter.com/gadievron
Who is next?
My original post on this:
http://gadievron.blogspot.com/2008/08/washington-post-atrivointercage-why-are.html
Gadi Evron,
ge@linuxbox.org
Follow me on twitter! http://twitter.com/gadievron
Friday, August 29, 2008
Washington Post: Atrivo/Intercage, why are we peering with the American RBN?
This Washington Post story came out today:
http://voices.washingtonpost.com/securityfix/2008/08/report_slams_us_host_as_major.html
In it, Brian Krebs discusses the SF Bay Area based Atrivo/Intercage, which has been long named as a bad actor, accused of shuffling abuse reports to different IP addresses and hosting criminals en masse, compared often to RBN in maliciousness. "The American RBN", if you like.
1. I realize this is a problematic issue, but when it is clear a network is so evil (as the story suggests they are), why are we still peering with them? Who currently provides them with transit? Are they aware of this news story?
If Lycos' make spam not war, and Blue Security's blue frog were ran out of hosting continually, this has been done before to some extent. This network is not in Russia or China, but in the silicon valley.
2. On a different note, why is anyone still accepting their route announcements? I know some among us re-route RBN traffic to protect users. Do you see this as a valid solution for your networks?
What ASNs belong to Atrivo, anyway?
Anyone has more details as to the apparent evilness of Atrivo/Intercage, who can verify these reports? As researched as they are, and my personal experience aside, I'd like some more data before coming to conclusions.
Hostexploit released a document [PDF] on this very network, just now, which is helpful:
http://hostexploit.com/index.php?option=com_content&view=article&id=12&Itemid=15
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
http://voices.washingtonpost.com/securityfix/2008/08/report_slams_us_host_as_major.html
In it, Brian Krebs discusses the SF Bay Area based Atrivo/Intercage, which has been long named as a bad actor, accused of shuffling abuse reports to different IP addresses and hosting criminals en masse, compared often to RBN in maliciousness. "The American RBN", if you like.
1. I realize this is a problematic issue, but when it is clear a network is so evil (as the story suggests they are), why are we still peering with them? Who currently provides them with transit? Are they aware of this news story?
If Lycos' make spam not war, and Blue Security's blue frog were ran out of hosting continually, this has been done before to some extent. This network is not in Russia or China, but in the silicon valley.
2. On a different note, why is anyone still accepting their route announcements? I know some among us re-route RBN traffic to protect users. Do you see this as a valid solution for your networks?
What ASNs belong to Atrivo, anyway?
Anyone has more details as to the apparent evilness of Atrivo/Intercage, who can verify these reports? As researched as they are, and my personal experience aside, I'd like some more data before coming to conclusions.
Hostexploit released a document [PDF] on this very network, just now, which is helpful:
http://hostexploit.com/index.php?option=com_content&view=article&id=12&Itemid=15
Gadi Evron,
ge@linuxbox.org.
Follow me on twitter! http://twitter.com/gadievron
Subscribe to:
Posts (Atom)