11 ms·
Cloudflare blocks an almost 2 Tbps multi-vector DDoS attack
- donkarma 5y agoI always thought there should be more terabit attacks with the level of home connections nowadays
- leros 5y agoI would imagine ISPs have some sort of bot prevention measures that would get triggered if you went all out on using a home connection.
- pixl97 5y agoIn general, no. Unless you start affecting their internal network. If you keep the traffic rather moderate a home connection can spew traffic for months on end.
- jchw 5y agoA good mitigation strategy is giving people 1Gbps down, over DOCSIS 3.1, that nobody can ever actually hit, and overselling significantly on top of that. Then, doing the same with upload, but only offering around 30Mbps up. At least that’s how it feels in the U.S.
- short12 5y agoAt my last apartment it was gigabit. And it was definitely gigabit speeds
- watermelon0 5y agoCoax cable is limited to 10 Gbps (DOCSIS 3.1) and is shared with many houses/apartments (can easily be a few hundred modems) in a neighborhood. Theoretically only 10 people can use 1 Gbps at any one time, in practice probably even less.
- kordlessagain 5y agoThere are at least 65 million homes in the US.
- catlikesshrimp 5y agoLol??? 5mbps x 200,000 subscribers is already 1 tbps We all need faster speeds at home, not slower. Counter suggestion: make fcc regulate iot, whenever a person's appliance enters a botnet, suspend his connection until said appliance is removed and fine the person if the device wasn't fcc aproved. There, no more botnets inside the US. The rest of the world to go
- dpifke 5y agoThe FCC as regulator is an interesting idea. Appliances sold in the US already have to prove they don't create harmful EMF emissions. It wouldn't be much of a stretch to add minimum security requirements to avoid harmful "data emissions" to that same certification process.
- rolisz 5y agoSo you can't make your own devices anymore?
- makapuf 5y agoYou could say you should take care of making them right. And add a few safety rules if you want to sell them.
- fragmede 5y agosure you can. but the instant they're part of a botnet attacking someone, you, it's owner, should have to do something about it. We have fire code to regulate what people build so they're not a death trap and this wouldn't be so different.
- NullPrefix 5y agoHow would you certify that a windows PC won't join a botnet?
- fragmede 5y agoI wouldn't. But when the device, which happens to be running windows, takes part in a DDOS attack, I wish we could do something about that, rather than have to buy our way out of the problem by having a bigger pipe and sinking traffic, because it means that you have to be blessed by the powers that be of the Internet(Cloudflare, AWS, GCP, etc) in order to stay online in the face of a DDOS attack.
- fpgaminer 5y agoIt's my understanding that 1000/30 isn't an artificial limitation. The coax lines have limited bandwidth such that 1000/1000 per customer just isn't possible. They could split it different ways, of course, but since historically most customers download far more than they upload the 1000/30 became standard among consumer ISPs. Not that ISPs aren't evil. They were paid to run fiber everywhere, such that everyone would have 1000/1000 fiber links by now. But such as it is.
- jchw 5y agoDOCSIS is asymmetrical, but my understanding is that 3.1 could theoretically handle 10000/1000 with all channels. I’m sure the infrastructure in many places wouldn’t be able to do that, but I have a feeling they could do better than 30.
- tbrock 5y agoCertainly even 50/500, or 100/500 would be a better split.
- t0mas88 5y agoSome have, but it's usually signature based. If a customer has an infection with a known worm (all I've seen were windows based) it's matched by some signature and the connection is isolated. From then on all web traffic is redirected to the ISPs service portal helping the customer install an antivirus solution. Never seen it applied to DDoS kind of things.
- ransom1538 5y agoThey do! I have a fast fiber connection. I have had an ISP sec/ops guy literally call me and ask about my traffic patterns. He was more curious than anything -- but they do monitor strange patterns. I agreed to turn off my crawlers and explained it wasn't a botnet.
- wilde 5y agoI assume you live outside the US? Our home connections here haven’t improved in two decades.
- 14 5y agoCan’t they try take the bots offline? Do the bots hide their IP address or could they not start contacting the owners of said ip addresses and tell them they need to remove the infected device from the internet? I know it wouldn’t be that easy but is there nothing they can do to fight back and start getting rid of these bots?
- pixl97 5y agoHow long does it take to contact thousands and thousands of IP owners looking for infected device? Many of which are behind NAT devices which require even further tracing. What about the ones overseas that just don't care?
- zeusk 5y agoIn past, they have taken bots offline (mainly by taking over the Command/Control server) but most of these "bots" are just malware infected connected devices operated by clueless average folks - hard to update, hard to take down.
- buro9 5y agoThe article mentions that these were UDP attacks... which are usually reflections based on spoofed IP addresses. So who should Cloudflare contact? In the meantime another few hundred small attacks arrive. It's more constructive to improve the capability to mitigate attacks as they and other network providers have agency over that.
- josefx 5y agoThe UDP packets still have to pass through the network and networks can attach all kind of tracking headers to these packets. So you should be theoretically able to track down the sources of long running attack if every network provider along the line cooperates.
- spiffytech 5y agoUDP doesn't have a notion of key/value headers of arbitrary data (like HTTP does). This is all the metadata that UDP packets include: https://en.wikipedia.org/wiki/User_Datagram_Protocol#IPv4_pseudo_header https://en.wikipedia.org/wiki/User_Datagram_Protocol#IPv4_ps... If cooperation of intermediary networks is assumed, these attacks can be crippled by convincing ISPs to deny outbound UDP packets claiming source IPs from outside their networks.
- Ansil849 5y ago> The entire attack lasted just one minute. Did the attack last one minute because Cloudflare 'mitigated' it after that, or because the attackers stopped?
- buro9 5y agoBotnets tests their capabilities all the time. This could have been a command and control test, a test to see what they could muster, or a demonstration. When testing they seldom run for a long time. Cloudflare's mitigation would've dropped in on the metals and still been visible to Cloudflare's monitoring... so the attackers stopped after a minute.
- remram 5y agoSo those nice graphs on Cloudflare's blog are exactly the information the attackers wanted? If that's the case, by publishing such detailed post-morterms, Cloudflare is just inviting future test attacks.
- toast0 5y agoI used to run the servers for a popular website. It was common to get DDoSed targeting our servers (or more frequently, just a single one out of the group) for exactly 90 seconds (plus or minus a few systems that had poor ntp synchronization). Whether or not that took my servers down, the attack would stop. To my knowledge, we never got any communication from the people behind the attack, seemed like people just kicking the tires on DDoS as a service. Ocassionally, we'd get a longer interval, sometimes 60 minutes.
- raspyberr 5y agoI've read that Cloudflare also hosts a lot of DDoS-for-hire services. That seems like a conflict of interest.
- winternett 5y agoThis is 2021, where almost everyone creates a global problem, then makes money off of being the one to "mitigate the problem"... The people dedicated to not creating new problems, but trying genuinely to fix problems simply fail and/or run out of money are increasingly ignored because they don't have the biggest marketing budgets. Honesty isn't making money any more... A huge problem. The absence of any real accountability, and admiration of hypocrisy, is what threatens us most heading into the future.
- systemvoltage 5y agoI am not convinced, do you have any sources that prove your conspiracy?
- winternett 5y agoOh No... No... Not me!... :P Not really a conspiracy theory... Just a personal opinion. These days sharing "conspiracy theories" get people banned online and worse... Just made as a statement in reply to the parent comment, but if you watch the commercials during television news, you might perhaps wonder how "Restless Leg Syndrome" became a real thing, and why there's now how conveniently there is a drug that claims to "fix it" if you're willing to sacrifice diarrhea for in exchange for the pill's implied benefits.
- secondaryacct 5y agoDude, Cloudflare is not encouraging ddos to then benefit from it, it existed and will exist with or without them.
- cedilla 5y agoYour ignorance of a neurological disorder before you watched a commercial about it doesn't imply it's an invention. Restless leg syndrome has been described for centuries.
- short12 5y agoWhat is with ddos these days? Are they doing it for money ? It just seems silly with services like cloud flare
- catlikesshrimp 5y agoYou can hire a ddos agaisnt your across the street competitor. It could be the other pizzeria, the other hardwareshop. Use your imagination
- short12 5y agoThat used to be a thing but is it anymore? There is so much mitigation so it's pretty much ineffective
- nightfly 5y agoNot everyone has mitigation. If you know your competitor is hosted by a small hosting outfit you can get them banned from their webhost by directing a DOS attack at them.
- gavinray 5y agoIt's even worse nowadays than it used to be, due to "Serverless" and "Infinite Scalability"/"Auto-scaling". One of the most fascinating things I've read recently is the rise of "Denial-of-Capital" attacks. Essentially, you DDoS a competitor, but not directly in the interest of just taking them offline. Instead (hopefully) running up a massive cloud bill and putting them out of business. Or a similarly critical financial hit. If you don't have billing limits enforced for all of your services, and you run auto-scale/serverless workloads in any part -- if someone can pass enough traffic to your services they can cause you potentially incredible financial grief. Most recent (publicized) one I can think of is this one. Fathom Analytics attacks: https://news.ycombinator.com/item?id=25194795 https://news.ycombinator.com/item?id=25194795 There was an initial cloud bill, but now they're paying $3,000/mo for AWS to have a Cloud Protection team on standby for them. "$36,000 & my call with Fola" "I don’t know anybody who has signed up for this $3,000/month service from AWS… it’s called AWS Shield Advanced. The big value of this service to us is that we have access to some of the world’s best DDoS mitigation experts. In the event of an attack, we can page them, and they’ll help us mitigate the attack, creating firewall rules, identifying bad actors, and offering advice. So instead of just two of us responding to DDoS attacks, we have genius engineers we can speak with, and that feels good." Ouch.
- taf2 5y agoAssuming this is about telnxy outages this week and their migration to cloudflare. https://status.telnyx.com/ https://status.telnyx.com/ Maybe premature for cloudflare to be declaring victory?
- BuildTheRobots 5y agoWhilst I'm a big fan of people updating status pages, copy/pasted updates really rub me up the wrong way.
- schleck8 5y agoThere is a truly excellent video on Mirai's (the botnet or atleast code in question) origin. It was created in the Minecraft server community by teenagers. The botnet was huge to a point where Akamai had to get help from Google to mitigate an attack on krebs' security blog. It also was used to attack Dyn, the infrastructure provider, and resulted in a huge outage affecting Netflix, Twitter etc. Sadly it's only in German, but if you are on desktop, you can auto-translate the subtitles. https://www.youtube.com/watch?v=uletKRPMnuo https://www.youtube.com/watch?v=uletKRPMnuo
- maxgashkov 5y agoI was responsible for a website (one of a many of this kind) that provided access to a niche auction platform. At some point in the beginning of 2010s it became a subject of a precisely coordinated series of timed attacks designed to disrupt bidding of one of our prominent clients in the specific auctions. It was enough to bring down the service for ~5 minutes to prevent the client from winning. Eventually we migrated behind CF and the problem was solved but I couldn't help but wonder if there are some applications for which even a few seconds disruption (I assume that's the minimum time Cloudflare needs to begin effectively mitigate the attack of this scale) will be disastrous and what could possibly be done in this case?
- iimblack 5y agoStock trading comes to mind
- toast0 5y agoIf you can't handle a few seconds disruption, you really need actually private networking. Dedicated lines (or at least dedicated wavelength on shared fiber) and redundancy and very fast failover. Volumetric udp reflection isn't really too bad to process anyway, as long as you've got the bandwidth --- fancy tricks get you from the UDP stack dropping useless packets to dropping useless packets without the UDP stack, possibly at the edge without using up nearly as much internal bandwidth. Where it gets pretty hard to manage would be application level bursts, IMHO.
- krebsonsecurity 5y agoCF: Would it be asking too much to have a date and time stamp on your blog posts somewhere?
- dmd 5y agoIt's right below the title, where you'd expect it.
- IYasha 5y agoWhatever, guys... Nothing, NOTHING will make me think better of CloudFlare. I won't forgive you, CF, for captcha, tracking and blocking me from accessing a critical server from an airport! Burn in hell!