Study on DoS Activity In The Internet
Random Walk writes "A group of researchers from the UCSD Supercomputer Center has used a
technique they call "backscatter analysis" to study
the prevalence and targets of DoS attacks. They claim that
their study is
"the only publically available data quantifying
denial-of-service activity in the Internet", and
provide interesting statistics on attack rates, durations, and victims." CT:This is an amazing report.
What version of DOS is it up to now? 6.2? 7.0? And does anyone know the nake of a good DOS web browser? Hell, I thought DOS was dead. Good to see some people still using it.
I found the paper really interesting. The methods and techniques seem reasonably sound for establishing a lower bound for "significant" attacks. But I'm disturbed that in the midst of the IPv4 address-space crunch where getting a /19 out of ARIN is practically impossible, the researchers were allowed to use a /8 network that was totally unutilized (or if that wasn't true, their data are seriously problematic).
They say themselves -- they were monitoring backscatter traffic by observing any traffic sent into an unused network address space comprising 1/256th of the total IPv4 space.
This just in:
In what many people are calling a sick twist of fate, the Supercomputer Center was hit with a Denial of Service attack shortly after issuing a study on the prevalence and target of DoS attacks. While details are sparse at this point, that attack is rumored to have been a "Slashdot-effect" attack. The leader of the "Slashdot" group of hackers, CmdrTaco, could not be reached for comment. His partner in crime, Hemos, was quoted as saying, "Ph34r the sl4shd0t 3ff3ct!" More details to follow as they become public..
That these places always publish their documents in some wimpy quiche-eating format like PDF and postscript only?
PDF and postscript are excellent for hardcopies, but they're not distributing hardcopies. They're distributing electronic copies.
I suppose it's just WAY too difficult to run their PDF through a filter to convert it from PDF to HTML or text. Of course, I could do it myself, but I'm a slashdot poster, and I whine, I don't actually do anything proactive.
-- Truth goes out the door when rumor comes innuendo. -- Groucho Marx
Microsoft's DNS actually went down two days in a row. The first day was a router misconfiguration. I remember because a lot of my office was having problems with IE loading its default homepage (msn.com). After checking things out it was pretty clear that even with an ip address from whois for their dns servers that traceroutes died at an MS router. i.e. you could get to the DNS router that was doing the round robin for the DNS servers, so it wasn't being DoSed. Go to this Wired article where Microsoft spokespersons admit that it was a router misconfiguration. And we know that Microsoft's PR people are always putting down Microsoft products and services as being the worst.
After the 23 hours it took Microsoft to figure out it had a bad router config, the skript kitties obviously decided that this poor router had to be rebaptised in a stream of packets, a veritable flood of packets. I don't condone it, but the fact that MS took 23 hours to figure out they had a bad router config causing them a DoS and took another few days to decide that they should outsource their DNS to someone who could provide a distributed and reliable service shows a top heavy beast that could not compete without the monopoly (District Court ruling stands until the Milton Friedman acolytes on the Appeals Court hand down a verdict as a resume addendum to Dubya for selection to the Supreme Court.) power that they possess.
Maybe a little off topic but congress just published a report on FBI's National Infrastructure Protection Center. It deems the FBI imcompetent and nothing more than a incident report function. DOS is covered in details. TheRegister has a good write up today.
Help fight continental drift.
From the article in the first few paragraphs, talking about denial of service attacks:
Microsoft's name server infrastructure was disabled by a similar assault.
No it wasn't. Microsoft just fucked up with the ONE router that had their DNS traffic going through it.
Makes me want to give up reading if it's going to be crap like that.
Bah.
--
Delphis
Delphis
As somebody who has had to deal with the fallout of these attacks more than once, I would say no. They are never justified. If you are flooding enough traffic to affect the target, you are almost certainly affecting lots of other people who just happen to share a pipe with the target. If you DoS some web site, what do you think that does to other sites on the same server? Other folks who just happen to be at the same co-lo site? What about the folks who just happen to have the same local or upstream ISP? Is it OK for me to DoS you because I don't like your neighbor? Is it OK for me to DoS all of optonline.net because I don't like your political views?
Even if you accept the premise that it's OK to DoS innocent people, a DoS is a piss-poor political statement. No body is going to notice at all. If I find that riaa.org is unreachable, am I going to suddenly telepathetically reach some conclusion about their politics? No. If you want to make a political statement, you have to actual say something. Merely screaming nothing at the top of your lungs accomplishes nothing.
Could be. Of course, considering that CmdrTaco's contribution to this story consisted of the words "random," "walk," and "writes," I'd suggest that the shell script theory might be somewhat flawed in this case.
So CmdrTaco is posting as Hemos now?
--
--
"Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
English is not my mothers tongue but I have this feeling that an insecure computer would be a form of artificial intelligence.....
"The likes of Facebook and WhatsApp are free to those whose privacy is of zero value."
/. forgot to mention that the paper is in PDF or PostScript.
:P
I don't understand, they always seem to mention that fact and the fact that the NY Times is a free registration.
--
Why would Romania be on someone's shitlist?
Ethics II Axiom 2. "Man thinks." B. Spinoza
Regardless, their study is probably useful at gauging the frequency of attacks that aren't truly massive enough to attract widespread notice. Some of those do seem to reveal more sophistication than this technique would catch. Yahoo attacks and the Microsoft DNS attack seem to have revealed a certain amount of awareness of network structure. But as a technique of measuring attacks that aren't otherwise widely reported, this study is an order of magnitude more interesting than anything I've seen before.
I've personally noticed what I believe to be "backscatter" - large, brief ping floods that are too small or brief to be an actual DoS.
Boss of nothin. Big deal.
Son, go get daddy's hard plastic eyes.
Expanding a vast wasteland since 1996.
Try reading the paper before you post. It is one of the best things I have read on the subject, and addresses the things that are being "pointed out" in previous posts. (not a troll, just a recommendation)
Its just like any violent protest. Everyone has a breaking point.
I'm not sure if its a very good form of protest, it might get a few lines in a newspaper article but doesn't make for good film at 11.
The surprise isn't how often we make bad choices; the surprise is how seldom they defeat us.
--
+1 Insightful, -1 Troll. What can I say, I'm an Insightful Troll.
You can view Stefan Savage (one of the paper's co-authors) giving a lecture on his findings at http://stanford-online.stanford.edu. The lecture is only about 50 minutes. Click on "View Free Seminars" and then on the link for "CS548 Internet and Distributed Systems Research Seminar". The lecture is from May 16th.
Sorry, the only format is streaming Windows Media.
-Sverker
Nicely written document although they should have focused likewise on posting some methods to circumvent DoS attacks. Many networking, and security admins, know of the problems arising from DoS, yet there are scores of them who know little about protecting their infrastructure from an attack.
Personally I think its a trivial job to halt denials of service attacks, but it can be done, and what someone should create is a framework for ISP's, Colleges, whoever has a networking propagating info out, to follow that shows them how to enable engress filtering so no attacks come out of their network, and an equally likewise doc that shows preventive measures.
Everyone, and their BOFH mother thats on the net, knows the effects of a DoS attacks, or what a DoS attack is, but a fraction of them know what to do about it.
Anyways for some of those admins, I have a doc called Stopping DoS which is a die hard "this-is-what-you-do-on-this-hadware" to limit DoS attacks, as well as a s(emi)tudy paper called "Theories in DoS" which is a higher protocol level look at Denials of Service, which provides a framework look into future avoidances of them.
P.S. These are docs I wrote out of spare time, etc. nothing more, so don't expect any RFC based documents such as this paper thats linked.
Want Root?
1) Right now, any insecure computer can be cracked for use in a DoS attack, thereby indirectly implicating an innocent person. Anyone can get hijacked in this way and framed for another attack, particularly if the investigators choose not to trace back to the original source.
This is something that is bugging me right now. I got myself cracked on New Year's Eve. It was my own stupid fault, I had forgotten to patch ftpd and some little wiener had installed a root kit through it. As luck would have it I was in bed with the flu and happened to notice the flashing lights on my cable modem so I got the machine unplugged right away.
Here's the thing that's bothers me. If I hadn't noticed for a day or two and the script kiddie had gone and used my machine as a place to crack from or if he used it as a node is a DDOS attack how responsible am I. It is partialy my fault the machine got comprimised but how much trouble could I get in when the federales came and busted down my door. I honestly belive that if some subsequent attack had been traced back to my box and the feds found out it ws owned by a mid 20s UNIX geek type guy I could really been in for some grief. I would at least get all my machines confiscated for "evidence".
Something to think about anyways.
What someone should really do is set up a kernel module and/or userspace app that reports unusual packets back to a data-gathering server. Because the reporting machines would be scattered all over the place there's no practical way to avoid them, and they'd get a good pool of backscatter.
Of course, the data-gathering server would probably get DoSed in short order...
--
314-15-9265
Sorry. Should have checked the coordinator name for 44.0.0.0/8: "Kantor, Brian (BK29-ARIN) brian@UCSD.EDU". Looks like this was the block they were using, then.
my plan
GROGGS: alive and well and living in
No. This is wo be self-administered justice and cannot be justified.
KdenLive/PIAVE - non-linear video editing
Analyzing the backscatter traffic from attacks is actually a very well-known technique among firewall admins and other security practitioners.
lcamtuf's wtfs project, for instance, has successfully used this kind of distributed monitoring to discover many interesting probes, including Hotmail's stealthy reverse tracerouting, strange behaviour from f5 load balancers, as well as many actual attacks and scans, by monitoring unused /16s and random hosts across the net.
The key is to go after the zombies but also go affter the traffic. I was not shocked by the findings of the report but I've gotta wonder how much of this DoS tarffic is eating up bandwith that I've gotta pay for.
So I guess there are even non-political, ethical justifications for DoS attacks.
Moreso, isn't DoS precisely what companies like Mercury Interactive and Keynote do when they try to slam your webserver so you know whether you need to buy more server processing power, etc.?
--
I think I own a porno of the same name. *Ba-doom sha* Another example of a worthless study clogging /., please for the childrens sake, stop the insanity!
What, me worry?
What do you mean, "replaced"? ;-)
--
Let's send these guys the address of any little site that's being Slashdotted.
Men believe what they want. - Caesar
Slashdot reads like CmdrTaco has been replaced by a very small shell script. Every other article is "interesting", if a hard disk is mentioned he will tell us "personally" how he would use it for MP3s, and any display technology will be used to play games. Not to mention the same spelling errors over and over again. Has Slashdot become a Turing test or what?
At the beginning was at.
I was expecting the number of DoS attacks to be higher. Being on IRC a lot, I see a number of small single user DoS attacks made.
PortSentry, the stateful firewall I use on my linux box, picks up a ton of attempts from .ro domains. A friend of mine had his box owned by a .ro. Someone from a .ro host ran a CGI-scanner against one of my commercial websites, generating about 3,000 404 email reports in 10 minutes. A lot of fraudulent orders (on that same site) come from IPs in Romania.
I get more problems from Romania than I do from Russia. For a country with such a "poor networking infrastructure," they have no shortage of crackers and carders. And it doesn't surprise me in the least that they're getting their punk asses DoS'd!
Shaun
Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
No. Ddos is repression.. If the anger of the Ddos attackers keep me from expressing my ideas or reading the ideas of others they are repressive. Ddos is a theft, you are stealing bandwidth I paid for. Ddos attacks keep network engineers busy on resolving them instead of improving thruput and maintainig systems I paid to use. There is NO excuse ever.
As you can see I don't care about my karma.
This report sounds similar to the "Resiliance of the Internet to Random Breakdowns" report that was on Slashdot a while ago, from the Online Journal Publishing Service (Physical Review Letters, or something). While, yes, in theory, the Internet could still operate with 99% of its nodes nonfunctional, most of the content of the Internet would be lost in the 99% that went down.
It seems like it would be similar here. I will state right off that I have not had the time to read the article yet, since I'm writing this message from on the job, but it sounds to me like it's just looking at raw numbers, and not the implications of those numbers. The sites that were attacked were high-profile sites, such as Amazon.com, yahoo.com, ebay.com, microsoft.com, and such - sites that the orchestrators were trying to make a point by attacking. If you look at the number of machines used, etc... you get an idea of the attacker's technical savvy, but not necessarely their motives.
Anaylizing raw data is good, but when it comes to humans, it is very hard to reduce human behavior down to a series of numbers in a table. Of course, my conclusion may change on reading the paper in more detail later this afternoon.
Seven out of ten statisticians say that all statistics are meaningless.
While I am pleased that there is a scientific mapping of DoS attacks I would like to take the opportunity to point out certain dynamics in DoS attacking, particularly if used as a disinformation and political tool by government.
1) Right now, any insecure computer can be cracked for use in a DoS attack, thereby indirectly implicating an innocent person. Anyone can get hijacked in this way and framed for another attack, particularly if the investigators choose not to trace back to the original source.
2) DoS and other infowar techniques have been used by the political opponents of Indymedia and other "subversive" websites. I am not referring to the Indymedia subpoena related to the Quebec protests, which was referred to earlier on this site, but to the simple denial of service that crashes these things when they are needed most.
3) Lets say that there is, hypothetically, some politically motivated DoS going on. If so, it;s quite silly and wasteful. The sites that are being DoS'ed are usually those prominent targets, big corporations and government sites which are sometimes capable of holding off attack but are always capable of sending many goons after you. Might I suggest that there are more effective ways of using technology as a political tool.
Goat sex free since 2001
Owing to the potential for malfunctioning devices, misconfigured systems, etc. to generate traffic that might appear as a DoS attack under their definitions (they stuck to flooding attacks), I wonder if they drew a line, below which something did not qualify as an attack? And if so, where did they draw the line, and how many script kiddies' actions fell below it?
For your security, this post has been encrypted with ROT-13, twice.
Most networks have a single route to the rest of the internet. directing traffic through this router is a lot more likely to cause problems than packets that are handled within the network.
A limitation that makes more sense is "valid" ip addresses only. And it's simple to do - just pick a class A like 198.* that way you eliminate 10.* and 255.* which are might be filtered before they reach the main router. Since most IP's are valid (in that they get routed somewhere) this only makes a tiny difference in attack performance, but hey - every little bit hurts.
The statements above do not necessarily reflect the authors opinion.
Interesting... I'm a writer, and a while back I had an idea for a novel about a group of grey hats called JiHAD who would go around bombing, cracking, DoSing, etc., etc. various parties opposed to free speech & human rights etc.
The concept would be something akin to Spiderman: wisecracking hero, hated and pursued by cops, but who does manage to give the bad guys their just desserts (tangling with a web, appropriately enough...)
The first chapter would involve our hero, on the anniversary of the Halloween memo incident, anonymously bringing to light hundreds of incriminating documents that he has "liberated" from some of M$'s most private servers....
What do you think? Do you think it has potential?
"Anything is better than IE, and you can quote me on that." -- Wil Wheaton.
I just don't understand it. I got moderated down as "offtopic". Since when did humor have to be "on topic"? Some folks got no sense of humor, I guess...
CERT appears to be conducting some additional research in this field right now. http://news.cnet.com/news/0-1003-200-6016900.html
Was I the only one to find this funny?
Quoted from the article above:
*begin quote*
3.3 Analysis limitations
There are three assumptions that underly our analysis:
* Address uniformity: attackers spoof source addresses at random.
*end quote*
This seems to me to be a currently acceptable assumption IFF the attacks are of an unsophisticated/sophomoric nature; however, if the attackers are attempting to cause maximum utilization of the target network's resources, the attackers most likely will not use a randomly distributed source address. In fact, the optimal employment of spoofed addresses will likely be some subset of the addresses employed by the target's network.
It seems likely in light of this that the "backscatter technique" outlined here, while useful, may not record the attacks engineered by more sophisticated attackers.
Nietzsche on Diku:
sn; at god ba g
:Backstab >KILLS< god.
While we're on the subject, I'm interested in the Slashdot community's opinion on DoS. Is anyone in support of it in special circumstances? For example, would you support it if it were politically justified? I'm not talking about anything and everything one disagrees with, but what about cases of blatant human rights violations? Comments?
----------What the Chiquita banana?