How to investigate and mitigate brute force attacks
LevelBlue Completes Acquisition of Cybereason. Learn more
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
LevelBlue Completes Acquisition of Cybereason. Learn more
Why bother to pick a lock if you can simply kick in the door?
That’s the logic behind the brute force attack, one of the most common of all security exploits. The idea behind brute force is simple: simply try all possibilities until you find the one that works. Typically, there is no prioritization of some possibilities over others. Instead, all are tried systematically in a simple sequence, such as alphanumerical.
Brute force attacks fall, generally speaking, into two classes. The more common involves an online resource or service, such as an e-mail service; here, the hacker attempts to find a correct password. Offline brute force attacks, on the other hand, are less common because they involve trying to decrypt a file (such as a UNIX password file), and thus require obtaining the file in the first place.
As a group, all brute force attacks combined are (according to a recent McAfee Security Report) the second-most common of all exploit types (behind denial of service), amounting to some 25% of the total. WordPress sites in particular are often hit with such attacks in order to obtain control of the publishing platform and leverage it for malicious purposes.
What’s the motive behind a brute force attack? The most obvious is also the most common: privileged access to restricted data, applications, or resources of all kinds.
In some cases, a brute force attack is also a logical stepping-stone or pivot point — by brute-forcing to point A, it’s then possible to launch subsequent exploits (perhaps of a different type) to get to points B-Z. The hacker may also seek to install something such as a rootkit, add a new bot to a botnet, create a command and control center for a botnet, or (if possible) simply steal money or sensitive information (such as credit card numbers or banking credentials) that lead directly to money.
So how can you spot a brute force attack while it is happening? No single indicator is certain, but these are all logical possibilities:
Many failed log-ins from the same IP address. This is a particularly strong sign (though if the attacker is using a botnet, IP addresses will obviously vary).
Toward fending off a brute force attack, a variety of straightforward options include:
Unfortunately, brute force is a class of attack that’s unlikely to vanish any time soon. Going forward, in fact, it’s clear that brute force attacks are likely to become both more prevalent and more effective.
This is a simple consequence of the fact that the more computational power you have, the faster and more successful a brute force attack is likely to be, all other factors being equal. And in today’s world of botnets, not to mention scalable grid and cloud architectures, computational power is relatively cheap and easy to get.
In the near future, in fact, artificial intelligence may even be applied to simplify/prioritize the brute force process by focusing on the most promising possibilities first. This being the case, security professionals will have to stay on their toes.
LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.