Online Networks Face New Stealth Attack

HELSINKI — All network security equipment is facing a new kind of online attack, according to Finnish data security vendor Stonesoft.

The company said earlier this week that it has found a new threat category — advanced evasion techniques (AETs) — which simultaneously combine different evasions in several layers of networks and in the process, become invisible for security gear, such as a firewall.

"From the point of view of cybercriminals and hackers, advanced evasion techniques work like a master key to anywhere," said Klaus Majewski, business development chief at Stonesoft.

"Current protection against advanced evasion techniques is next to zero,” he said. “This is a new thing and there is no protection against it currently. It's unlikely that really any network security vendor is aware of such evasions.”

The problem with advanced evasion techniques — tools hackers often use to penetrate network security — is not just new attacks, but that AETs can create millions of combinations from a few dozen different evasions.

Tim Henning, ASACP’s vice president of technology, told XBIZ these evasion techniques are a form of a stealth attack, allowing attackers to bypass most firewalls and intrusion detection and prevention systems without being detected.

“Current security systems don’t have a defense against this,” Henning said. “Most networks have a vulnerability, so it sits there undetected until it finds a way to get into the network and deliver a virus.”

Henning said these evasions have global ramifications from a cyber attack to possibly affecting security, financial, banking networks and online vendors.

For online adult companies, Henning said hackers could grab all of a customer’s information, including credit card numbers and other sensitive material.

Henning urged network owners talk to their department that deals with security on their servers and take the following steps to best protect this kind of attack at the moment:

  • Examine your current network

  • Ensure your current network secondary defenses are adequate and up to date such as anti- virus and malware solutions. Examine a layered approach to network security if already not in place and if in place ensure it's adequate to best protect your network

  • Be watchful for unexplained network events such as server crashes without an explanation being found for the event

  • Contact the vendors of your current IDS/IPS (intrusion detection and prevention systems) such as firewalls and ask what they are doing to protect against AETs and what you can do to protect against it until a solution is found and implemented.

“People need to focus on secondary lines of defense,” he said. “If someone does get in, they have other security solutions in place to be able to prevent delivery of a virus.”

Stonesoft has alerted authorities about its findings and it thinks others have also likely found similar technologies.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Sansyl Group Acquires Blue Donkey Media

Sansyl Group, parent company of AdultPrime Network, has acquired Blue Donkey Media B.V., owner of Dutch adult site Meiden van Holland, among several other erotic websites and television channels.

Pineapple Support to Hold Mental Health Summit

The annual Pineapple Support Mental Health Summit is taking place Dec. 15-17.

Ofcom Fines AVS Group $1.3 Million for AV Noncompliance

U.K. media regulator Ofcom on Wednesday imposed a penalty of one million pounds, or approximately $1.3 million, on AVS Group Ltd. after an investigation concluded that the company had failed to implement robust age checks on 18 adult websites.

Updated: Aylo to Help Test EU Age Verification App

Pornhub parent company Aylo plans to participate in the European Commission’s pilot program for its “white label” age verification app, a spokesperson for the company has confirmed.

Missouri Lawmaker Attempts to Revive 'Health Warnings' for Adult Sites

A Missouri state representative has introduced a bill that would require adult sites to post notices warning users of alleged physical, mental, and social harms associated with pornography, despite a previous federal court ruling against such requirements.

New Age Verification Service 'BorderAge' Launches

French startup company Needemand has officially launched its subscription-based age verification solution, BorderAge.

Ruling: Italy's 'Porn Tax' Applies to All Content Creators

Italy’s tax revenue agency has ruled that the nation’s 25% “ethical tax” on income generated from adult content applies even to smaller independent online content creators.

Proposed New Hampshire AV Bill Appears to Violate Constitution

A bill in the New Hampshire state legislature, aimed at requiring adult sites to age-verify users in that state, contains a provision that seemingly contradicts the Supremacy Clause in Article VI of the U.S. Constitution.

AEBN Publishes Report on Fetish Trends

AEBN has published a report on fetish categories from its straight and gay theaters.

Online Child Protection Hearing to Include Federal AV Bill

A House subcommittee will hold a hearing next week on a slate of bills aimed at protecting minors online, including the SCREEN Act, which would make site-based age verification of users seeking to access adult content federal law.

Show More