Bleepingcomputer Residential Proxies Compromise IP Reputation Systems in Cyber Attacks
Article Content
- •78% of malicious sessions evade detection by IP reputation systems due to residential proxies.
- •Residential IPs are often used briefly, complicating threat detection and response.
- •Major disruptions to proxy networks result in quick regeneration of malicious traffic.
A recent analysis by GreyNoise revealed that residential proxies are being used to evade IP reputation checks in 78% of 4 billion malicious sessions observed over a three-month period. These proxies, often originating from compromised devices, make it difficult for security systems to distinguish between legitimate users and attackers. Approximately 39% of malicious sessions come from these residential IPs, which typically last for fewer than three sessions before rotating. The study indicates that 89.7% of residential IPs are involved in malicious activities for less than a month. Major contributors to this issue include networks from China, India, and Brazil, with traffic patterns reflecting human usage, dropping significantly at night. The research highlights the ineffectiveness of traditional IP reputation systems against the rapid rotation of these proxies. Notably, the Google Threat Intelligence Group recently disrupted one of the largest residential proxy networks, IPIDEA, which had millions of active proxies. However, the disruption led to an increase in datacenter traffic, suggesting that demand for such proxies remains high. The findings emphasize the need for new detection strategies beyond IP reputation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…