CSOonline conducted Q&As with Jerry Mangiarelli, a security specialist with TD Bank in Canada, and Israeli researcher Gadi Evron.
A corporate security specialist on motives and tactics Jerry Mangiarelli has gained a lot of private-sector perspective on the DDoS threat over the years through his own personal research into botnets. He's a frequent speaker on the subject at such security conferences as EC-Council, SecTor and FSP. Here, he gives examples of what his research says about hacker tactics and motives.
CSO: What was it that shifted your focus so heavily into the area of bot-related DDoS attacks? Mangiarelli: The shift was influenced by my continued interest/research in malware and the application layer. The adversaries' motives that we've witnessed over the years as botnets mesh with the application layer is that there's a lot of return-on-investment (ROI) for them.
Describe what goes into your research in terms of hours spent and tools used. Mangiarelli: I spend a considerable amount of time researching. I like to call it my nightshift after the kids are in bed. I spend the time evaluating tools used by adversaries specifically around the development of Web-based DDoS toolkits.
The link for this article located at CSO Online is no longer available.