4 ms·
Anycast isn't difficult to implement and is widely used to create CDNs. It is simply costly. You need to buy a large block of IPs and have multiple data centers
by codexon 13y ago
Anycast isn't difficult to implement and is widely used to create CDNs. It is simply costly. You need to buy a large block of IPs and have multiple data centers.
After you have that, it is trivial to block all DNS packets, especially due to the fact that Cloudflare doesn't need to receive DNS packets on their public endpoints because they only serve HTTP traffic.
- sillysaurus2 13y agoHmm, is it very hard to DDoS DNS servers? I'm a bit confused about the DNS part of what you said.
- codexon 13y agoNot to be rude but if you don't understand what I just said, you might want to re-read the article you just cited.
- sillysaurus2 13y agoYou are being rude, but I care about learning more than rudeness, so if you'll kindly help me out: But DNS servers can also be queried for the IP addresses of huge swaths of the Internet, putting the person listed as making the request on the receiving end of a massive response. In a blog post published Wednesday, CloudFlare CEO Matthew Prince said each DNS request sent by the Spamhaus attackers was likely only 36 bytes long, while each response was about 3,000 bytes. By spoofing the requests to make them appear as if they originated with Spamhaus, the attackers can turn the firepower of all those networks against their opponent, all but guaranteeing it won't be available to process legitimate traffic. I'm still not really getting it. Which IP addresses are they referring to when they say "huge swaths of the internet"? To get Spamhaus back online, CloudFlare relied on Anycast, a routing technique that distributes the same IP address across 23 data centers across the world. Internet traffic almost always chooses the shortest physical path. Anycast allows the geographically dispersed junk traffic to be absorbed by dozens of individual centers, where each packet is then inspected. When it bears signatures found in the attack traffic—for example, if it's a 3,000-byte response from an open DNS resolver—it is discarded in the CloudFlare data center. Only Legitimate Web requests are allowed to be forwarded to the Spamhaus data center. How do they differentiate between a legit query and a DDoS query?
- imbriaco 13y agoThe "huge swaths of the internet" part is poorly phrased in the article. What they're basically saying is that there are a large number of DNS servers on the Internet that allow anyone to query them. Attackers query those servers and forge the source address that the query originates from such that it points at the IP address of their target. The attacker needs only send 36 bytes of data to the DNS server and the server responds with up to thousands of bytes of response -- directly at the target of the attack. I don't know precisely how CloudFlare mitigated it but I can make some guesses: - They may have just blocked UDP traffic on their edge. Since their DDoS mitigation service is specifically for HTTP and HTTPS, UDP is safe to simply drop. - They may have determined that the attack responses had payloads that fell within a size range, and configured their mitigation hardware or routers to drop packets in that size envelope. - They may have analyzed inbound UDP traffic to see what open resolvers were flooding them and surgically blocked UDP traffic from those IPs.
- codexon 13y agoI'm sorry but it is clear to me that you don't understand a major portion of the article you are telling people here to read as though you can understand the technical details. This is both disturbing and amusing at the same time. If I am coming off as rude and people are going to downvote me for pointing this out, then so be it.
- girvo 13y agoYou are being rude, and I don't know how you got that from this new users post. You'll be downvoted because of those facts.
- codexon 13y agoWhat facts? You mean the fact that he is telling HN that it is a technical marvel to block such a large attack and then he doesn't even understand how the attack was done as was explained in the article he told people to read? This is a clear example of how the signal to noise ratio on Hacker News is going way down.
- 13y ago
- pizzeys 13y agoIs it trivial to block all DNS if your core business is serving records over DNS, though?