Feeds

Botnets fuel internet DDoS insurgency

Attacks top 100Gbps for the first time

The essential guide to IT transformation

Updated Distributed denial of service attacks topped 100Gbps for the first time last year, during which attempts to flood websites with junk traffic went mainstream.

Major incidents in 2010 included DDoS attacks associated with pro- and anti-WikiLeaks hackers and militias as well as hacking attacks linked to political turmoil in Burma and Sri Lanka, according to the latest annual study by DDoS mitigation experts Arbor Networks. The DDoS mitigation firm saw the maximum attack traffic in the most ferocious attack exceed 100Gbps1 for the first time last year.

Botnets of compromised PCs once again served as the launchpad of countless attacks. Website packet-flooding attacks and more sophisticated application-layer attacks have been the mainstay of such activity but last year attacks targeting telecoms services – DNS (Domain Name System), VoIP and IPv6 – became more commonplace, according to the report. In particular, attacks against DNS servers have increased, mainly because it is relatively easily to floor such servers (even in cases where they are correctly configured and even more so when config problems come into play). Taking out DNS services would leave a majority of surfers unable to reach a targeted website.

Both data centre and telecoms service providers told Arbor that application-layer DDoS attacks are leading to significant outages. In response, many service providers have set up stateful firewalls and intrusion prevention system (IPS) devices to protect data centre infrastructure. Unfortunately these devices can act as a bottleneck when deployed in front of web servers, becoming overwhelmed by even a moderately powerful DDoS assault. Nearly half (49 per cent) of enterprises or operators surveyed experienced a firewall or IPS outage as the result of a DDoS attack.

"Network operators are facing a global Internet insurgency driven by the ubiquity of botnets," said Roland Dobbins, solutions architect with Arbor Networks. "This has led to rapidly escalating DDoS attack size, frequency and sophistication. Adding to the challenges facing operators is the increasing number of attack vectors, including applications and services, not to mention the proliferation of mobile devices." ®

1 The 100Gbps DDoS attack reported by a survey respondent was a DNS reflection/amplification attack, made possible by a combination of a lack industry-standard best practice anti-spoofing policy enforcement at network edges, coupled with the misconfiguration of a large number of DNS servers around the internet as open recursors.

The victim was an ISP, a customer of one of the network operators who took part in the survey, Arbor Networks explains.

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?