News: 1593079412

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

There are DDoS attacks, then there's this 809 million packet-per-second tsunami Akamai says it just caught

(2020/06/25)


Akamai reckons it blocked what may be the largest distributed denial-of-service attack ever, in terms of packets per second.

The content delivery network [1]today said it successfully warded off the mammoth traffic flood, even as it was hit with a peak load of 809 million packets per second (PPS).

The attack, which began on 21 June, was directed at an unspecified European bank. The security team told The Register it is the largest such attack Akamai has ever encountered, let alone blocked, and the CDN believes that it is likely the largest DDoS attack to hit any network, in terms of packets per second.

"We believe this is a new industry record for PPS-focused attacks, and well over double the size of the previous high-water mark on the Akamai platform, just one week after Akamai announced another massive DDoS attack," Akamai said in its report on the digital tsunami. "Looking holistically at DDoS activity since the onset of 2020, it is clear that large, sophisticated DDoS attacks are still a significant attack vector."

Akamai could not say if there was any ulterior motivation behind the barrage (ie, to use the DDoS as a distraction) but the security team told El Reg that the bank in question has had to deal with fairly frequent attacks, so it might just be the latest (and largest) of a number of attempts to knock the institution offline.

DNS this week stands for Drowning Needed Services: Design flaw in name server system can be exploited to flood machines offline [2]READ MORE

What was unusual to the Akamai researchers was how the attack began and ended (or was mitigated) with extraordinary speed.

"The attack grew from normal traffic levels to 418Gbps in seconds, before reaching its peak size of 809Mpps in approximately two minutes," Akamai said. "In total, the attack lasted slightly less than 10 minutes."

For what it's worth, Amazon Web Services [3]claimed in May it mitigated a 2.3Tbps flood against a target, though Akamai claims it stopped a larger attack, in terms of packets per second.

The assault was not only large in volume, but also in source. It is believed that the botnet wrangler behind the flood was in command of a massive number of infected PCs, many of them being used as part of a DDoS attack for the first time.

"It was highly unusual that 96.2 per cent of source IPs were observed for the first time (or at a minimum, were not being tracked as being part of attacks in recent history)," the Akamai team explained.

"We had observed a number of different attack vectors coming from the 3.8 per cent of remaining source IPs, both matching the single attack vector seen in this attack and aligned to others. In this case, most of the source IPs could be identified within large internet service providers via autonomous system (AS) lookups, which is indicative of compromised end-user machines."

Unfortunately, Akamai believes that these sort of high-volume DDoS operations are only going to continue, and possibly even grow further. The CDN noted that it had tracked another massive attack in the week prior to the June operation, and financial services (along with internet and telecoms) are among the most popular targets. ®

Sponsored: [4]Free Hands-on Training: Anthos Service Mesh



[1] https://blogs.akamai.com/2020/06/largest-ever-recorded-packet-per-secondbased-ddos-attack-mitigated-by-akamai.html

[2] https://www.theregister.com/2020/05/21/nxnaattack_bug_disclosed/

[3] https://aws.amazon.com/blogs/security/aws-shield-threat-landscape-report-now-available/

[4] https://go.theregister.com/tl/1956/-9050/free-hands-on-training-anthos-service-mesh?td=wptl1956

And the next step...

lglethal

Can Akamai pass the IP addresses from which they got the attack to the various ISP's, so that the ISP's can contact the associated end user and suggest they give their machines a thorough cleaning?

Otherwise, I dont really see a difference to the police stopping a bank robbery in progress, identifying the perps, and then saying "Ah well, its too hard to go and grab these crooks at their home address. We stopped them from stealing anything, so we'll just forget this ever happened..."

That's not going to stop the next attack, now is it...

Re: And the next step...

Version 1.0

You can report IP addresses to ISPs but nothing ever happens.

Do you really think that anyone would believe a call today that says, "We've detected that your computer is infected, please download this file to clean it up"?

Re: And the next step...

Wade Burchette

Not only that, because of malvertising and illegal robocallers, I would be very suspicious of any message about cleaning up your computer.

Solution, Billing = $

john.jones.name

Quite easy

Bill the endpoint

This incentivizes both the ISP and the End User

The ISP can do it easily enough within the existing T&C's because their was "effort" to process the IP logs, say $10 which is waived instantly if they phone/email and declare they have cleaned up their network/PC/router

That would be attractive to the ISP (sicne people are lazy they get to keep a portion) and reward people who take care... (while educating people to the cost)

honestly I don't know why they don't do it...

Re: Solution, Billing = $

Ben Tasker

What happens when I find out your IP, decide I don't like you and regularly flood Akamai with UDP packets with the source address being yours so that you get billed? Even if you say "I've cleaned it", your ISP is going to get dubious quickly.

Not to mention, there are a lot of ISPs who couldn't be trusted with that responsibility

Re: And the next step...

alain williams

Can Akamai pass the IP addresses from which they got the attack to the various ISP's, so that the ISP's can contact the associated end user and suggest they give their machines a thorough cleaning?

What they need to do is to speak to a few of the ISPs and get traffic logs for some of these PCs. Try to work out the command & control addresses - these are the real ones to chase - not the hapless users running a compromised Microsoft machine. Maybe examine a few of these machine to see what malware they have.

It will be interesting to see who the botnet controllers are: criminals or governments (mind you sometimes they are the same thing).

Re: And the next step...

Anonymous Coward

not the hapless users running a compromised Microsoft machine.

Nice assumption there. I think you'll find a high proportion of these sorts of attacks come from compromised routers and other devices, rather than desktops or laptops.

Re: And the next step...

Anonymous Coward

"come from compromised routers and other devices"

Which simply reinforces alain's comment that it's "not the hapless users" that need to be chased. (But definitely go after the ISP that provides a hackable device, like mine with TR-069 enabled and world-accessible, with no way to turn it off, and tech support not knowing what that is.)

As an end user (and small server owner), I'd love for my ISP to notify me if there's malware-related traffic coming from my systems. Though they'd definitely have to prove it's really them and not "Windows" calling...

The tip of the iceberg

Version 1.0

I'm seeing big increases in malware delivery attempts at levels that I have never seen in 20 years, an attack like this looks normal. Worldwide Covid reactions are changing how many people work and cracking the door for attacks, thefts, and malware deliveries - we need to start working on a new Internet, what we have today is effectively broken, filled with spam, malware, and everyone's personal data being sold from one company to another.

Re: The tip of the iceberg

disgustedoftunbridgewells

The only way to achieve that is a more hierarchical design which is the opposite of a good thing.

Please use an explicit test - I know gcc suggest just an extra set of
parenthesis, but I'm personally convinced that is just because some gcc
people have been damaged by too much LISP.

- Linus Torvalds discussing gcc requirements on linux-kernel