Download presentation
Presentation is loading. Please wait.
Published byBartholomew Francis Modified over 8 years ago
1
Black + White = Grey Ethical Issues Surrounding the Creation and Distribution of Hacker Tools Used in Distributed Denial of Service Attacks Joseph Levine February 29, 2000
2
Background Mid-1999 distributed DOS software begins to appear in public hacking & security forums August 17, 1999 University of Minnesota attacked by a network of hundreds of systems running Trinoo (aka Trin00) November 2-4 1999 CERT hosts workshop for 30 top security experts on “Distributed-Systems Intruder Tools” February 7, 2000 Yahoo effectively taken offline by distributed denial of service attack
3
Why DDOS Is Different Security exploits are published daily. Most security problems relate to a specific issue that can be corrected by vendors. Denial of service vulnerabilities are hard to eliminate.
4
Why DDOS Is Different Distributed denial of service attacks are even more difficult to address. Determining the true source of a distributed attack is very complicated, meaning that attacks may take longer to stop and attacker are more difficult to catch.
5
Common Tools
6
Basics of A DDOS Attack
7
Where Do These Tools Come From? Underground Networks of sophisticated hackers write tools like the ones being discussed here. Some are released to the public by individuals who claim to desire only to allow people to protect themselves. Once source code is available many more people can create their own variants making detection more difficult
8
What Benefits Do Distributed Denial of Service Tools Provide? Increased general awareness of security issues Security Analysts can review source code to learn more about the exploit Authors gain respect amongst their peers
9
What Problems Do These Tools Present? Lowers the minimum skill level required to execute a distributed attack Decreases the amount of effort required to execute a distributed attack Availability of source code for these tools allows them to evolve rapidly
10
Who is responsible? Anyone who uses these tools is clearly responsible for their own actions Authors of these tools are at fault as well. By providing a simple tool kit to commit crimes they are morally responsible for the crimes being committed.
11
Conclusion Creating distributed attack tools like Tribal Flood Network is ethically wrong. Researching vulnerabilities fine, as is writing reports detailing problems. Releasing functional code or binaries that have no use other than harming others is ethically wrong.
12
Questions
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.