A Third of the Internet Experienced DoS Attacks in the Last Two Years (sciencedaily.com)
Long-time Slashdot reader doom writes: Over a two year period, a third of the IPv4 address space have experienced some sort of DoS attack, though the researchers who've ascertained this suspect this is an underestimate. This is from a story at Science Daily reporting on a study recently presented in London at the Internet Measurement Conference.
"As might be expected, more than a quarter of the targeted addresses in the study came in the United States, the nation with the most internet addresses in the world. Japan, with the third most internet addresses, ranks anywhere from 14th to 25th for the number of DoS attacks, indicating a relatively safe nation for DoS attacks..."
The study itself states, "On average, on a single day, about 3% of all Web sites were involved in attacks (i.e., by being hosted on targeted IP addresses)."
"Put another way," said the report's principal investigator, "during this recent two-year period under study, the internet was targeted by nearly 30,000 attacks per day."
"As might be expected, more than a quarter of the targeted addresses in the study came in the United States, the nation with the most internet addresses in the world. Japan, with the third most internet addresses, ranks anywhere from 14th to 25th for the number of DoS attacks, indicating a relatively safe nation for DoS attacks..."
The study itself states, "On average, on a single day, about 3% of all Web sites were involved in attacks (i.e., by being hosted on targeted IP addresses)."
"Put another way," said the report's principal investigator, "during this recent two-year period under study, the internet was targeted by nearly 30,000 attacks per day."
I installed Win95 on my DOS system. Am I safe?
What I'd actually like to hear about are alternate designs that could be used to create a net without vulnerability to denial-of-service.
I wonder, what is the ratio of per capita DoS attacks between sites that use the ASCII character set for their URL and sites that use other character sets for the URL? Is there a preference for victims using ASCII for the URL that's stronger than preferences based on the geographic location of the site owner?
All of this is possible
Has there ever been a +5 Flamebait?
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
Acutally, the handful of times I've traced back attacking IP's during a significant DDoS attack (3+Gb/s) I found the attacking IP's to be web servers from small to medium businesses running the LAMP stack. The most common was a php file was uploaded to the server and simply executed via the web server due to misconfiguration. Not surprisingly contacting the owners of the compromised servers never yielded any response - but one I did contact I saw that about a week later the offending php file was gone as attempting to execute it via web browser resulted in a 404 when previously it did not. This was only about 3 or 4 years ago, too.
I mean, jeez, Mozilla, why is Firefox so friggin' SLOW?
Here in Oz, last evening it was obvious the Internet was slowing down drastically, oh wait I'm on the NBN....
My home modem is subjected to 50 meg ddos attacks every day. I think the "1/3'd" cited is pretty much a low ball. My web servers see 1 gig attacks just about every day, and my mail servers see at least 1 million emails per day rejected based on nothing more than it's RIR space. We won't even discuss what is going on with port 22 since I do not allow password PAM and require a key. If you are in APNIC, LATNIC, BRNIC, and much of RIPE space, sorry. It's firewalled completely for all ports. (Except for the UK, no one using my stuff needs the others.)
Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves.