TP240PhoneHome Reflection/Amplification DDoS Attack Vector
akamai.com
akamai.com
If open peering and the open Internet are to survive I think serious work needs to be done to fight DDOS attacks. It needs to be an effort analogous to the "war on spam" in the late 1990s / early 2000s. Unfortunately that war was sort of lost; e-mail is in practice barely an open protocol anymore and almost all e-mail is handled by a few giant companies that can leverage big data to filter spam. If you try to DIY a mail server you'll be simultaneously hit by spam and have to constantly fight mistaken filtration by larger e-mail providers who tend to distrust small mail servers by default.
If the open Internet succumbs to DDOS "spam," we will lose something really huge and important. It would be the ultimate casualty of what so far has been almost a law (with very few exceptions): all open systems are destroyed by abuse if they become sufficiently popular.
We also can't just leave it to the free market because the only solution the market will likely come up with is walled gardens. It's the easiest to engineer solution and the easiest to monetize.
All the networks of the Internet are already private, just like the networks of AOL and CompuServe were private back in the day: your ISP's network is private, YouTube's network is private, AWS' network is private. It's just that those private networks agree to talk to each other.
Otherwise your ISP would have to re-create YouTube and Reddit/forums and eBay/marketplace and…, and YouTube would have to buildout (inter)national network to connect their video services to people's homes.
Just like AOL and CompuServe had to build out information services and a connectivity infrastructure back in the day.
Now each of the previously walled gardens (messaging, forums, marketplaces, connectivity, etc) is done by its own entity, each taking a slice of the monetary pie for the service(s) they provide.
The Internet is a 'network of networks', but it is also an agreement: an agreement for everyone to talk to everyone else.
I have managed my own e-mail server for around 20 years.
Filtering spam has never been a problem.
On the other hand your second problem has indeed existed, i.e. with various large e-mail providers which either blocked completely my e-mail messages without signalling any error, or they delayed for 1 day or 2 my messages, or they required many resendings of a message until really passing it to the destination.
Fortunately such cases seem to have become much more seldom during the last couple of years.
Coordinated disclosure: https://blog.cloudflare.com/cve-2022-26143/
Info for Cloudflare customers: https://blog.cloudflare.com/cve-2022-26143-amplification-att...
This seems like it would exceed that in many cases, since 1 byte in => 4.2 gigabytes out. Which is roughly 33.6 gbps. Not sure many of these vulnerable boxes actually have that amount of outbound bandwidth to utilize.
(Please feel free to correct my quick math if I messed it up)
Another interesting impact of this is that the higher the amplification, the more likely it is noticeable by the server that is being abused. I mean if you clog the outbound network for a company they will notice and try to resolve immediately. Versus some milder amplification where it can go under the radar, or at least the business impact urgency radar of a company much longer.
at 4 billion to 1, there's in practice very little difference between CVE-2022-26143 and what you describe. Both will be capped at the same number by the bandwidth available to the offending system.
Once that hits, the device would then be sending the traffic harmlessly to /dev/null for the next 14 hours and be unavailable for attacks.
Not sure about the legal and ethical implications of that.
Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.
[0]- In the US; I don't know about anywhere else
Surprisingly enough, the ISP often has no real way of contacting anyone; the easiest is to cut the connection and wait for a complaint.
In the case of this TP240 attack, you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with a vendor to patch it, you're still tasked with somehow getting 2600 businesses to patch their systems or modify firewall rules.
In the case of the memcached amplification attack, Cloudflare saw upwards of 5800 source IPs in the attacks, and Shodan reported nearly 88000 IPs responding on port 11211 [1]. Tracking down the owners of 88k installations across public clouds, businesses, probably some residential networks, is a monumental task. There's nothing easy about it.
[1] https://blog.cloudflare.com/memcrashed-major-amplification-a...
You can be sure that by only null-routing their entire C-class, adjacent customers will loudly complain to the operator who will quickly identify the source and disconnect it. The best way to deploy fixes on the net has always been to first disconnect them. This way you don't have to convince anyone, it's done the other way around. Typically the CEO will instantly throw all the phones to the trash to get the net opened again.
Unless you have coordination with the network operators on which those amplifiers are sitting, your null-routing of the amplifier in your own network isn't going to stop it from attacking other targets. If the amplifier is something like a DNS server, then your collateral damage isn't just "adjacent customers", it's potentially thousands of other users and resolvers on your own network. If those amplifiers are on a cloud service provider like AWS, you're going to potentially inflict even more pain onto your own paying customers who will no longer be able to communicate with AWS. You will essentially perform the DoS they were aiming for.
You are liable unless you can pass off that liability to someone else. So the ISP would be liable by default, and would have an incentive to filter their customers, or require them to abide by certain rules, pass some audits, provide proof of insurance or post a large deposit.
You could have insurers who in exchange of automated security scans will insure you, solving the problem for end-users at a reasonable cost.
This will actually encourage internet users (both consumers and businesses) to take security more seriously.
A major issue here is how your smart toaster or MiVoice box can be spamming the internet and there's no real way to realize it for most people.
Since you pitched a controversial solution, let me make one that's probably even more controversial: maybe bandwidth is too cheap. Maybe the problem would fix itself without legal hell if your C&C'd smart toaster / VoIP box had an impact on your ISP bill instead of being folded into your unlimited bandwidth billing.
> Approximately 2,600 of these systems have been incorrectly provisioned so that an unauthenticated system test facility has been inadvertently exposed to the public internet
Isn't a primary responsibility of government to protect its citizens and businesses from other states' militaries?
The NSA has since turned away from this responsibility, and has done the exact opposite. When Dual_EC_DRBG was developed [2], there was a similar choice of constants, with the final values having been chosen by the NSA. In this case, rather than protecting against a attack method known only by the NSA, the constants were chosen to allow an attack method known only by the NSA.
[0] https://en.wikipedia.org/wiki/Data_Encryption_Standard
[1] https://en.wikipedia.org/wiki/Differential_cryptanalysis
https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)
stop simping for the nsa
Just because nobody has figured out (or bothered to invest into) building the equivalent of basic security doesn't mean it's the state's responsibility.
It is the government's responsibility to make sure companies take their responsibilities of protecting their customers' data, and the internet more broadly from the impact of the company's decisions.
Of course I'm not sure that's how it's playing out anyway, as I'm certain that the relevant three letter agencies are interested in foreign state actors digital incursions, it's just a very delicate situation and not as simple or clear cut as the Walmart example.
It's just a criminal act, of which Walmart are the victim, and it's the state's job to find and prosecute and deter that kind of thing from happening again.
There is no _must_ here. The police _must_ deter and punish crime. A private entity _may_ hire security if they find the police to be ineffective at stopping certain crimes. If walmart was robed while the security guard was off duty, it is still the police's job to investigate and arrest the criminal.
Besides, what ever happened to "provid[ing] for the common defense?"
Defending internet infrastructure from foreign government's attack is not "basic security".
For example:
We also have a tendency to conflate the requirements on software systems with respect to security threats as being somewhat similar to the requirements on other kinds of engineering with respect to safety and environmental threats, and I think that does a disservice to the vastly different scope of responsibility involved.
When I see people arguing that software engineers need to treat security as seriously as, say civil engineers treat structural stability when designing a bridge, or mechanical engineers treat vehicle crash safety, I agree to an extent, but I also think it’s worth considering:
Most bridges are not designed to actually survive being deliberately attacked with the kinds of weapons nation states can bring to bear on them. When militaries get involved, bridges tend to fail.
Likewise, civilian car safety testing does not make cars that are able to survive attacks that nation state actors can carry out with things like tanks, mines, or drones.
We need to be realistic in our expectations for what level of military threat civilian systems can reasonably be expected to deal with unaided.
Dropping bombs on a walmart store is clearly unwelcome, sending traffic to walmart's website? Much less clear. You can guess based on the traffic pattern but the only way to really know is to ask walmart if this is welcome traffic (not just a burst because some new product came out). Especially since many cases are DoS with encrypted TLS traffic that looks much like any other traffic to an outside observer.
However much of the protection is threat of retaliation ("if you drop bombs on us we will flatten your country"). So maybe that is the solution here, the government should treat these attacks as real threats and punish those responsible.
People can't do that, and it's a very basic defense.
It provides the first part of my post, authenticating the packages.
The second part is cutting out misbehaving connections. On this case on the article, it would be trivial, and governments should be on the ISP shoulders making them make call everywhere and cutting some of their clients. But there are many attacks where the ISPs don't have enough information to act if they implement something like BCP38.
In that context instantly jumping to "state-sponsored!" strikes me not only as a needless, but particularly dangerous escalation.
It's like people forget that "cyber" is most of all asymmetrical and attribution is usually more of a guessing game than an exact science.
Yet nearly every larger hack is very quickly labeled as some kind of "state sponsored offense!" to serve foreign policy narratives, and most of all; Excuse the incompetence that often enabled such attacks in the very first place.
Now ask yourself this question, would you like to give your military the full access to your infrastructure together with command and control capabilities to do with your devices and the software on them as it pleases according to the situation? If you actually think that in fact you are not okay with 24/7 monitoring and management from a centralized government institution, you should own up to your desires and get your defense together.
Of course, this is a simplistic and extreme scenario. Much of the missed part is about availability and basic institutional capability for military cyber operations, but the fundamental question is: when one demands something from the government, what exactly they wish to give up as a consequence of the proposed solution.
If you can't or don't want to secure it, don't put it online.
For one, we need to hold commercial vendors accountable - that means especially to refuse to provide security updates for the reasonably expected life time of a piece of software or hardware.
But especially, we need the companies using IT systems to be held accountable. The magic word is "defense in depth" - the scenario of the post we're talking about is a piece of equipment that was not supposed to be reachable from the Internet and despite that knowledge it was made accessible to the Internet. Seriously, anyone caught exposing dangerous stuff to Shodan should be fined to hell and back. Or to continue using your military comparison: most governments have laws that call for harsh punishment for "aid to the enemy" or similar. Time to update the law to the new digital world.
The government provides for the common security. That's one of it's most fundamental jobs.
Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.
Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable.
Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished.
We are at war with Russia and China on a nation-state level and on top of that we also have cybercrime gangs.
Yes! Because if you are a member of the state operated defense force, then defense is your responsibility. The state is responsible for defense.
If on the other hand, you are a civilian who just happens to own property near a border, you have absolutely zero obligation to defend the border yourself. The same is true for businesses near a border.
> We are at war with Russia and China on a nation-state level and on top of that we also have cybercrime gangs.
Man, if only society had a way to form some sort of governance body which could provide defense against other nations and provide some sort of justice system to protect against and punish crimes. Oh well, I guess its every man for themselves ¯\_(ツ)_/¯
Let's not say that. Suggesting that civilians have defence duties on par with members of the military is ridiculous.
Not aware of any country in the world that is currently in a declared state of war with Russia and China.
Just how much evidence do you need to realize that the actions of both Russia and China have been - for years now - to undermine Western societies and the global set of rules?
Another example of a government agency that fails at their job: the FDA. The FDA is supposed to protect consumers from harmful foods and medications, but the fact that you can walk into any store and grab a can of food or bottle of vitamins/supplements contaminated with heavy metals is a huge red flag [0][1][2][3][4][5]. The FDA does 0 product screening whatsoever. If the FDA actually did their job, healthcare revenues would be at an all time low in America. It pays off big time to have a diseased population.
[0] https://www.consumerlab.com/answers/supplements-and-foods-th...
[1] https://www.consumerlab.com/answers/do-zinc-supplements-cont...
[2] https://www.consumerlab.com/news/metals-in-seaweed-snacks/12...
[3] https://www.consumerlab.com/recalls/11882/herbal-supplements...
[4] https://www.consumerlab.com/news/contamination-in-greens-who...
[5] https://www.consumerlab.com/news/caution-with-spirulina-supp...