The expert appreciated the RCN's proposal to finalize the regulation of provider security
- Новости
- Internet and technology
- The expert appreciated the RCN's proposal to finalize the regulation of provider security


The proposal of Roskomnadzor (RCN) to finalize the legislative and regulatory documents regulating the cyber security of Internet service providers is more than correct and relevant, said Daniil Shcherbakov, Deputy CEO of Servicepipe. He told Izvestia about this on March 26.
In particular, the RCN intends to "expand the list of mandatory measures to protect against DDoS attacks, including the use of domestic solutions for monitoring and filtering traffic." Our experience of communicating with Internet service providers shows that about 73% of market participants do not have traffic analyzers, if we look at the largest players, this figure will be about 92%. The situation is not much better with protection against DDoS attacks - no more than 30% have protection in the entire market, and a maximum of 10% are protected among small players," the expert noted.
At the same time, he clarified that there has been a surge in hacktivist interest in attacks on telecom — since the beginning of the year, about 30 industry players have been targeted by intruders. Given that hacktivists have recently been using the tactics of multi-vector carpet attacks, without a traffic analyzer, and even more so without protection from DDoS attacks, Internet service providers are defenseless against this threat, the expert emphasized.
"For example, in one of the recent cases of hacktivist attacks on Internet service providers, the carpet attack lasted more than five days, went on both at the network and application levels, at the peak of the attack exceeded 7 gigabytes per second, the attack vectors were constantly changing and therefore it was necessary to constantly identify the attacked IP and send it for cleaning. Obviously, with such an attack without the ability to analyze traffic, protection is possible only by filtering all traffic, which is simply impossible in the case of telecom, and therefore an analyzer is needed," concluded Shcherbakov.
Earlier, on March 25, Roskomnadzor said that the providers' security system needed to be strengthened. The service noted that the current legislation needs to be finalized and updated. For example, it is necessary to consolidate the requirements for the stability of communication networks, within which telecom operators and providers will be required to ensure not only their protection, but also the ability to quickly recover from attacks.
Переведено сервисом «Яндекс Переводчик»