There are DDoS attacks, then there's this 809 million packet-per-second tsunami Akamai says it just caught
- Reference: 1593079412
- News link: https://www.theregister.co.uk/2020/06/25/akamai_809mpps_attack/
- Source link:
The content delivery network [1]today said it successfully warded off the mammoth traffic flood, even as it was hit with a peak load of 809 million packets per second (PPS).
The attack, which began on 21 June, was directed at an unspecified European bank. The security team told The Register it is the largest such attack Akamai has ever encountered, let alone blocked, and the CDN believes that it is likely the largest DDoS attack to hit any network, in terms of packets per second.
"We believe this is a new industry record for PPS-focused attacks, and well over double the size of the previous high-water mark on the Akamai platform, just one week after Akamai announced another massive DDoS attack," Akamai said in its report on the digital tsunami. "Looking holistically at DDoS activity since the onset of 2020, it is clear that large, sophisticated DDoS attacks are still a significant attack vector."
Akamai could not say if there was any ulterior motivation behind the barrage (ie, to use the DDoS as a distraction) but the security team told El Reg that the bank in question has had to deal with fairly frequent attacks, so it might just be the latest (and largest) of a number of attempts to knock the institution offline.
DNS this week stands for Drowning Needed Services: Design flaw in name server system can be exploited to flood machines offline [2]READ MORE
What was unusual to the Akamai researchers was how the attack began and ended (or was mitigated) with extraordinary speed.
"The attack grew from normal traffic levels to 418Gbps in seconds, before reaching its peak size of 809Mpps in approximately two minutes," Akamai said. "In total, the attack lasted slightly less than 10 minutes."
For what it's worth, Amazon Web Services [3]claimed in May it mitigated a 2.3Tbps flood against a target, though Akamai claims it stopped a larger attack, in terms of packets per second.
The assault was not only large in volume, but also in source. It is believed that the botnet wrangler behind the flood was in command of a massive number of infected PCs, many of them being used as part of a DDoS attack for the first time.
"It was highly unusual that 96.2 per cent of source IPs were observed for the first time (or at a minimum, were not being tracked as being part of attacks in recent history)," the Akamai team explained.
"We had observed a number of different attack vectors coming from the 3.8 per cent of remaining source IPs, both matching the single attack vector seen in this attack and aligned to others. In this case, most of the source IPs could be identified within large internet service providers via autonomous system (AS) lookups, which is indicative of compromised end-user machines."
Unfortunately, Akamai believes that these sort of high-volume DDoS operations are only going to continue, and possibly even grow further. The CDN noted that it had tracked another massive attack in the week prior to the June operation, and financial services (along with internet and telecoms) are among the most popular targets. ®
Sponsored: [4]Free Hands-on Training: Anthos Service Mesh
[1] https://blogs.akamai.com/2020/06/largest-ever-recorded-packet-per-secondbased-ddos-attack-mitigated-by-akamai.html
[2] https://www.theregister.com/2020/05/21/nxnaattack_bug_disclosed/
[3] https://aws.amazon.com/blogs/security/aws-shield-threat-landscape-report-now-available/
[4] https://go.theregister.com/tl/1956/-9050/free-hands-on-training-anthos-service-mesh?td=wptl1956
Re: And the next step...
You can report IP addresses to ISPs but nothing ever happens.
Do you really think that anyone would believe a call today that says, "We've detected that your computer is infected, please download this file to clean it up"?
Re: And the next step...
Not only that, because of malvertising and illegal robocallers, I would be very suspicious of any message about cleaning up your computer.
Solution, Billing = $
Quite easy
Bill the endpoint
This incentivizes both the ISP and the End User
The ISP can do it easily enough within the existing T&C's because their was "effort" to process the IP logs, say $10 which is waived instantly if they phone/email and declare they have cleaned up their network/PC/router
That would be attractive to the ISP (sicne people are lazy they get to keep a portion) and reward people who take care... (while educating people to the cost)
honestly I don't know why they don't do it...
Re: Solution, Billing = $
What happens when I find out your IP, decide I don't like you and regularly flood Akamai with UDP packets with the source address being yours so that you get billed? Even if you say "I've cleaned it", your ISP is going to get dubious quickly.
Not to mention, there are a lot of ISPs who couldn't be trusted with that responsibility
Re: And the next step...
Can Akamai pass the IP addresses from which they got the attack to the various ISP's, so that the ISP's can contact the associated end user and suggest they give their machines a thorough cleaning?
What they need to do is to speak to a few of the ISPs and get traffic logs for some of these PCs. Try to work out the command & control addresses - these are the real ones to chase - not the hapless users running a compromised Microsoft machine. Maybe examine a few of these machine to see what malware they have.
It will be interesting to see who the botnet controllers are: criminals or governments (mind you sometimes they are the same thing).
Re: And the next step...
not the hapless users running a compromised Microsoft machine.
Nice assumption there. I think you'll find a high proportion of these sorts of attacks come from compromised routers and other devices, rather than desktops or laptops.
Re: And the next step...
"come from compromised routers and other devices"
Which simply reinforces alain's comment that it's "not the hapless users" that need to be chased. (But definitely go after the ISP that provides a hackable device, like mine with TR-069 enabled and world-accessible, with no way to turn it off, and tech support not knowing what that is.)
As an end user (and small server owner), I'd love for my ISP to notify me if there's malware-related traffic coming from my systems. Though they'd definitely have to prove it's really them and not "Windows" calling...
The tip of the iceberg
I'm seeing big increases in malware delivery attempts at levels that I have never seen in 20 years, an attack like this looks normal. Worldwide Covid reactions are changing how many people work and cracking the door for attacks, thefts, and malware deliveries - we need to start working on a new Internet, what we have today is effectively broken, filled with spam, malware, and everyone's personal data being sold from one company to another.
Re: The tip of the iceberg
The only way to achieve that is a more hierarchical design which is the opposite of a good thing.
And the next step...
Can Akamai pass the IP addresses from which they got the attack to the various ISP's, so that the ISP's can contact the associated end user and suggest they give their machines a thorough cleaning?
Otherwise, I dont really see a difference to the police stopping a bank robbery in progress, identifying the perps, and then saying "Ah well, its too hard to go and grab these crooks at their home address. We stopped them from stealing anything, so we'll just forget this ever happened..."
That's not going to stop the next attack, now is it...