3 ms·
Not to be rude but if you don't understand what I just said, you might want to re-read the article you just cited.
by codexon 13y ago
Not to be rude but if you don't understand what I just said, you might want to re-read the article you just cited.
- sillysaurus2 13y agoYou are being rude, but I care about learning more than rudeness, so if you'll kindly help me out: But DNS servers can also be queried for the IP addresses of huge swaths of the Internet, putting the person listed as making the request on the receiving end of a massive response. In a blog post published Wednesday, CloudFlare CEO Matthew Prince said each DNS request sent by the Spamhaus attackers was likely only 36 bytes long, while each response was about 3,000 bytes. By spoofing the requests to make them appear as if they originated with Spamhaus, the attackers can turn the firepower of all those networks against their opponent, all but guaranteeing it won't be available to process legitimate traffic. I'm still not really getting it. Which IP addresses are they referring to when they say "huge swaths of the internet"? To get Spamhaus back online, CloudFlare relied on Anycast, a routing technique that distributes the same IP address across 23 data centers across the world. Internet traffic almost always chooses the shortest physical path. Anycast allows the geographically dispersed junk traffic to be absorbed by dozens of individual centers, where each packet is then inspected. When it bears signatures found in the attack traffic—for example, if it's a 3,000-byte response from an open DNS resolver—it is discarded in the CloudFlare data center. Only Legitimate Web requests are allowed to be forwarded to the Spamhaus data center. How do they differentiate between a legit query and a DDoS query?
- imbriaco 13y agoThe "huge swaths of the internet" part is poorly phrased in the article. What they're basically saying is that there are a large number of DNS servers on the Internet that allow anyone to query them. Attackers query those servers and forge the source address that the query originates from such that it points at the IP address of their target. The attacker needs only send 36 bytes of data to the DNS server and the server responds with up to thousands of bytes of response -- directly at the target of the attack. I don't know precisely how CloudFlare mitigated it but I can make some guesses: - They may have just blocked UDP traffic on their edge. Since their DDoS mitigation service is specifically for HTTP and HTTPS, UDP is safe to simply drop. - They may have determined that the attack responses had payloads that fell within a size range, and configured their mitigation hardware or routers to drop packets in that size envelope. - They may have analyzed inbound UDP traffic to see what open resolvers were flooding them and surgically blocked UDP traffic from those IPs.
- codexon 13y agoI'm sorry but it is clear to me that you don't understand a major portion of the article you are telling people here to read as though you can understand the technical details. This is both disturbing and amusing at the same time. If I am coming off as rude and people are going to downvote me for pointing this out, then so be it.
- girvo 13y agoYou are being rude, and I don't know how you got that from this new users post. You'll be downvoted because of those facts.
- codexon 13y agoWhat facts? You mean the fact that he is telling HN that it is a technical marvel to block such a large attack and then he doesn't even understand how the attack was done as was explained in the article he told people to read? This is a clear example of how the signal to noise ratio on Hacker News is going way down.
- MaulingMonkey 13y agoI'm still not really getting it. Which IP addresses are they referring to when they say "huge swaths of the internet"? Most IP addresses... most notably including the victim's IP address. Scenario: Attacker sends 36 byte DNS query with a falsified sender address (that of his victim) to, say, Google's DNS servers. If the origin isn't verified through something like IPsec, Google won't be able to tell that the sender was forged. Google then sends 3000 bytes to the victim, thinking they're simply replying to a request, whereas they're really (unknowingly) facilitating a DNS amplification attack (so called because the attacker turns e.g. 2Gb/s of botnet traffic to DNS servers into 200Gb/s of DNS responses to the victim.) Your random residential ISP may limit their DNS service to customers only -- unless the victim also happens to be a customer of said ISP (the very rare case), the victim's IP address will be refused service, and not sent a response. While this blocks "legitimate" requests (without forged senders) as well unless you're actually on that ISPs network, in practice this is rarely a problem -- DHCP is probably advertising the DNS servers which will respond to you on whatever network you're on. Aside from preventing other ISPs from having their customers freeload off your ISP's DNS server, this also prevents the attack (at least with regards to DNS servers.) How do they differentiate between a legit query and a DDoS query? CloudFlare, being on the sending side of the equation, can track what DNS requests are going outbound even without IPsec, and drop inbound responses which can't be matched up against one of those requests. That sounds expensive however. I imagine they do something much cheaper, like simply drop all inbound DNS traffic except the approved list of DNS servers that are probably advertised over DHCP anyways. Again, this can block technically "legitimate" requests where someone really did want to intentionally use some other DNS server, but again, rarely a problem.
- sillysaurus2 13y agoOh, hey, it's MaulingMonkey! How are ya? #gamedev 4 lyfe, yo. How is that old channel nowadays anyway? Thanks for the thorough and very clear explanation.
- MaulingMonkey 13y agoSame old same old.