4 ms·
> We observed 10s of millions of discrete IP addresses associated with the Mirai botnet that were part of the attack. (linked article) > ... the Mirai botnet w
by nmjohn 10y ago
> We observed 10s of millions of discrete IP addresses associated with the Mirai botnet that were part of the attack. (linked article)
> ... the Mirai botnet was at about 550,000 nodes, and that approximately 10 percent were involved in the attack on Dyn (from Level 3 CISO) [0]
Something really doesn't add up there - even if it turned out 100% of infected hosts in the Mirai botnet were targeting dyn (ie: 5.5 million nodes) - that still is a fraction of the number dyn is claiming.
[0]: https://threatpost.com/mirai-fueled-iot-botnet-behind-ddos-attacks-on-dns-providers/121475/ https://threatpost.com/mirai-fueled-iot-botnet-behind-ddos-a...
- dmourati 10y agoI believe Dyn's numbers are conflating two things: 1. The number of source IPs seen 2. The size of the botnet They are most certainly not equal because of spoofing.