DNSMadeEasy under major (over 50Gbps) DDoS Attack out of China
twitter.com
twitter.com
A more common mechanism used by real networks to mitigate these attacks in production is to pinpoint the target of the attack and offramp its traffic in the ISP core to a "regional scrubbing center" where advanced filtering tools (for instance, packet filters that can handle ACLs with high tens of thousands of terms) can try to sort through the crap.
The one scenario I can think of where that might be a problem is if they'd start flooding all the known hosts in a network for the specific purpose of overwhelming the routers. And even those hardware based filtering tools have upper limits.
Initially you don't have much to go on during such an attack and packet filtering is a reasonably expensive operation when you want to do it for a large number of hosts. So the strategy is to route all the traffic destined for that particular host through a router that has ACLs that are large enough to hold the total IP list for the botnet that is attacking the host, as these IPs become identified.
You don't want to route all your traffic through there because then you'd have to do the relatively expensive filtering on all of the packets, even those not destined for that particular host.
Now if an attacker were targeting the hosting facility they could thwart this strategy by sending requests to a larger number of hosts in the network in order to make life much harder for the crew fighting the attack. After all, you can't partition the problem anymore in to a portion that is targeted to the host and 'normal' traffic, effectively all the traffic could be bot traffic or it could be normal traffic, for all the receiving hosts.
To be able to partition the problem into a smaller one where you can let say 90% or more of the traffic through unfiltered and only concentrate on the remaining 10% would make solving it a bit easier. On the other hand if the attackers are silly enough to re-use the same bots to attack different hosts they've actually given you a clue as to which IPs are bots.
I hope that makes sense :)
* These attacks happen with shocking frequency (the major incentive ISPs have to mitigate them is not angry customers, but rather the drag it creates on their third-tier engineering staff to hunt down DDoS sources and craft ACLs for them)
* There is actually not a whole hell of a lot you can do about them, even if you light up a whole tier 1 core network with mitigation tools. At the end of the day, a well-crafted DDoS attack looks pretty much identical to normal traffic; if you can black-hole China to defeat an attack, it wasn't very cluefully done.
As a sidenote, I've been reading your posts for a while now and it seems you always have something insightful to say - cheers!
Is a domain provider like 1and1 a client of theirs or is my hosting provider a client?
This entry on Hacker News led me to wikipedia where I went from an article about Level3 to an article about Tier 1 Network to Internet Backbone. I feel like I'm on the verge of understanding more about how the internet works but it's all a bit above my head.
Maybe the target's data center is more ddos-proof than the one from easydns, extortionists go for the weakest link.
In this case - it really could be anything. The cost of one of these attacks is next to zero. Rarely will the botnet owner lose any machines resulting from an attack. The unfortunate thing after one of these attacks is you have no way of preventing it or going after the source.
More to the topic: It's much more likely that the motivations are financial.
It's about China bullying people around and trying to censor the internet.
As an example of how outdated a typical Windows XP install is in China, I'm running a site which has 95% traffic from China. Over 62% of users are on IE6.
However, most routers and firewalls also have a limit on packets per second they can process, on top of the throughput limits. I've got a 100Mbps commit on a 1000mbps pipe, and I can handle 1000Mbps of 'normal' traffic... but I got taken out a month back by a 200Mbps DDos that used very small packets. My router couldn't handle it. (now, if I had spent money on a better router, it wouldn't be a problem. As far as I can tell, even, a reasonable software router could have handled it.)
Another way to measure this is the capacity required to absorb the attack. You can get he.net bandwidth for around a thousand dollars a month per gigabit, and he.net is about as cheap as bandwidth gets, so to soak a 50 gigabit attack, you'd have to have fifty thousand dollars a month of spare capacity.
(I'm sure there are further discounts available between the 1GiB and the 50GiB tier... but you get the idea. )
50gbps would rank as one of the largest attacks I've ever heard of on the Internet. And I hear about quite a few of the really big ones. :-)
Sites that are routinely targeted for blackmail because they make lots of money have dealing with attacks like this down to a science. Of course they're not going to go out of their way to advertise that it happens all the time to protect their business interests, so that's why you may not have heard about it.
Banks and other financial institutions, gambling sites, large porn sites, top 100 websites and sites that are either vulnerable to brand damage or that have a lot of turnover see an awful lot of this.
50Gbps is at most 50K zombies or so, that's really not that bad.
The largest attacks against sites that I know of used a million ips and more. That's a wholly different kettle of fish and starts to be a real problem because even hardware based packet filtering (Thanks force10!) has its limits.
After a call with one of my hosting providers (yes, on a Sunday at that, how is that for service), they saw the 40Gbit barrier broken somewhere at the end of 2007, today they're prepared for a multiple of that but he says that because they are that well prepared they've become less of a target.
They've invested a very large sum of money in infrastructural components specifically to deal with DDOS attacks at the hardware level, and though he doesn't rule out the possibility that they'll be one day facing one they can't deal with he doesn't seem overly worried, he does not want to claim any upper limit.
The countries they've seen the most trouble from are hard to pin down, but apparently the former USSR states and China are pretty high on hist list for the 'bot masters'.
Extortion seems to have arrived on the internet to stay, if you're a small player and you become successful you'd better be prepared, sooner or later you'll be a target.
Even smaller websites can easily get 2 to 10 Gbps ddos attacks aimed at them, the first time this happened to me I was pretty happy that all that happened was that I received an email from my ISP informing me of the fact without any loss of service.
If you really want to know please drop me a line (email in my profile).
Not a single provider in the world can handle this kind of attack peacefully without service interruption except China Telecom and China Union.
Your calculations can't be more off about 50K bots, our counts showed more than 100K we couldn't count after that due to limitation in software.
My business has been dealing with DDOS attacks since 2002 we pretty much saw the brunt of every kind of new attack that came online. The only thing that can be compared with magnitude to this is the DNS Amplification attack, but that was limited in it's impact considering the source of the attack was diverse not from one geo area.
Yes, there will be an interruption, but you will be able to get the situation back under control while the attack is still in progress. You will need your upstreams/peers to collaborate.
If you're on the Cisco platform, then good luck to you.
I can't cite how I know, but if you look up who I am you can probably guess that I'm aware of the largest DDoS's in the world that take place.
http://www.webhostingtalk.com/showthread.php?t=970837&hi...
Another 30 gbps attack, discussion on webhostingtalk.com:
http://www.webhostingtalk.com/showthread.php?t=966658&hi...
Edit: interesting thread, apparently the reason it's 30gbps is that it's maxing out the link from China telecom, so legitimate Chinese customers are getting traffic dropped. FBI are involved. Suggested solution by some is to get traffic routed over more intercontinental links possibly via peering agreement with China Telecom, and beyond that political pressure.
While spam and DDOS attacks aren't directly comparable in terms of what they are, I'm speculating in terms of what negative effects continued and escalating DDOS attacks could have again in terms of laws, policies, white/blacklisting of entire networks/countries, and so forth.
Maybe its a rival DNS provider behind the attack?