19 ms·
Cloudflare blocks an almost 2 Tbps multi-vector DDoS attack
- short12 5y agoWhat is with ddos these days? Are they doing it for money ? It just seems silly with services like cloud flare
- catlikesshrimp 5y agoYou can hire a ddos agaisnt your across the street competitor. It could be the other pizzeria, the other hardwareshop. Use your imagination
- short12 5y agoThat used to be a thing but is it anymore? There is so much mitigation so it's pretty much ineffective
- nightfly 5y agoNot everyone has mitigation. If you know your competitor is hosted by a small hosting outfit you can get them banned from their webhost by directing a DOS attack at them.
- gavinray 5y agoIt's even worse nowadays than it used to be, due to "Serverless" and "Infinite Scalability"/"Auto-scaling". One of the most fascinating things I've read recently is the rise of "Denial-of-Capital" attacks. Essentially, you DDoS a competitor, but not directly in the interest of just taking them offline. Instead (hopefully) running up a massive cloud bill and putting them out of business. Or a similarly critical financial hit. If you don't have billing limits enforced for all of your services, and you run auto-scale/serverless workloads in any part -- if someone can pass enough traffic to your services they can cause you potentially incredible financial grief. Most recent (publicized) one I can think of is this one. Fathom Analytics attacks: https://news.ycombinator.com/item?id=25194795 https://news.ycombinator.com/item?id=25194795 There was an initial cloud bill, but now they're paying $3,000/mo for AWS to have a Cloud Protection team on standby for them. "$36,000 & my call with Fola" "I don’t know anybody who has signed up for this $3,000/month service from AWS… it’s called AWS Shield Advanced. The big value of this service to us is that we have access to some of the world’s best DDoS mitigation experts. In the event of an attack, we can page them, and they’ll help us mitigate the attack, creating firewall rules, identifying bad actors, and offering advice. So instead of just two of us responding to DDoS attacks, we have genius engineers we can speak with, and that feels good." Ouch.
- aliswe 5y agono such thing as billing limit in Azure, anyway.
- NullPrefix 5y agoAs if anyone signing up for Azure care about pricing.
- goodpoint 5y agoIneffective? It fuels cloudflare's business model.
- 1270018080 5y agoIf you have that much computing power at your disposal, you might as well just mine cryptocurrency, right?
- codsane 5y agoNot necessarily as this is Mirai, a botnet of IoT devices. There’s probably not much else you could do with them.
- remram 5y agoYou can probably do both at the same time, as cryptocurrency uses a lot of CPU/GPU/memory/... but little bandwidth, and DDoS typically uses bandwidth but little CPU/GPU/memory/...
- schleck8 5y agoThere is a truly excellent video on Mirai's (the botnet or atleast code in question) origin. It was created in the Minecraft server community by teenagers. The botnet was huge to a point where Akamai had to get help from Google to mitigate an attack on krebs' security blog. It also was used to attack Dyn, the infrastructure provider, and resulted in a huge outage affecting Netflix, Twitter etc. Sadly it's only in German, but if you are on desktop, you can auto-translate the subtitles. https://www.youtube.com/watch?v=uletKRPMnuo https://www.youtube.com/watch?v=uletKRPMnuo
- krebsonsecurity 5y agoCF: Would it be asking too much to have a date and time stamp on your blog posts somewhere?
- dmd 5y agoIt's right below the title, where you'd expect it.
- IYasha 5y agoWhatever, guys... Nothing, NOTHING will make me think better of CloudFlare. I won't forgive you, CF, for captcha, tracking and blocking me from accessing a critical server from an airport! Burn in hell!
- donkarma 5y agoI always thought there should be more terabit attacks with the level of home connections nowadays
- leros 5y agoI would imagine ISPs have some sort of bot prevention measures that would get triggered if you went all out on using a home connection.
- jchw 5y agoA good mitigation strategy is giving people 1Gbps down, over DOCSIS 3.1, that nobody can ever actually hit, and overselling significantly on top of that. Then, doing the same with upload, but only offering around 30Mbps up. At least that’s how it feels in the U.S.
- short12 5y agoAt my last apartment it was gigabit. And it was definitely gigabit speeds
- watermelon0 5y agoCoax cable is limited to 10 Gbps (DOCSIS 3.1) and is shared with many houses/apartments (can easily be a few hundred modems) in a neighborhood. Theoretically only 10 people can use 1 Gbps at any one time, in practice probably even less.
- kordlessagain 5y agoThere are at least 65 million homes in the US.
- catlikesshrimp 5y agoLol??? 5mbps x 200,000 subscribers is already 1 tbps We all need faster speeds at home, not slower. Counter suggestion: make fcc regulate iot, whenever a person's appliance enters a botnet, suspend his connection until said appliance is removed and fine the person if the device wasn't fcc aproved. There, no more botnets inside the US. The rest of the world to go
- 14 5y agoCan’t they try take the bots offline? Do the bots hide their IP address or could they not start contacting the owners of said ip addresses and tell them they need to remove the infected device from the internet? I know it wouldn’t be that easy but is there nothing they can do to fight back and start getting rid of these bots?
- pixl97 5y agoHow long does it take to contact thousands and thousands of IP owners looking for infected device? Many of which are behind NAT devices which require even further tracing. What about the ones overseas that just don't care?
- deleted 5y ago[deleted]
- zeusk 5y agoIn past, they have taken bots offline (mainly by taking over the Command/Control server) but most of these "bots" are just malware infected connected devices operated by clueless average folks - hard to update, hard to take down.
- buro9 5y agoThe article mentions that these were UDP attacks... which are usually reflections based on spoofed IP addresses. So who should Cloudflare contact? In the meantime another few hundred small attacks arrive. It's more constructive to improve the capability to mitigate attacks as they and other network providers have agency over that.
- josefx 5y agoThe UDP packets still have to pass through the network and networks can attach all kind of tracking headers to these packets. So you should be theoretically able to track down the sources of long running attack if every network provider along the line cooperates.
- 5y ago
- Ansil849 5y ago> The entire attack lasted just one minute. Did the attack last one minute because Cloudflare 'mitigated' it after that, or because the attackers stopped?
- toast0 5y agoI used to run the servers for a popular website. It was common to get DDoSed targeting our servers (or more frequently, just a single one out of the group) for exactly 90 seconds (plus or minus a few systems that had poor ntp synchronization). Whether or not that took my servers down, the attack would stop. To my knowledge, we never got any communication from the people behind the attack, seemed like people just kicking the tires on DDoS as a service. Ocassionally, we'd get a longer interval, sometimes 60 minutes.
- buro9 5y agoBotnets tests their capabilities all the time. This could have been a command and control test, a test to see what they could muster, or a demonstration. When testing they seldom run for a long time. Cloudflare's mitigation would've dropped in on the metals and still been visible to Cloudflare's monitoring... so the attackers stopped after a minute.
- remram 5y agoSo those nice graphs on Cloudflare's blog are exactly the information the attackers wanted? If that's the case, by publishing such detailed post-morterms, Cloudflare is just inviting future test attacks.
- raspyberr 5y agoI've read that Cloudflare also hosts a lot of DDoS-for-hire services. That seems like a conflict of interest.
- winternett 5y agoThis is 2021, where almost everyone creates a global problem, then makes money off of being the one to "mitigate the problem"... The people dedicated to not creating new problems, but trying genuinely to fix problems simply fail and/or run out of money are increasingly ignored because they don't have the biggest marketing budgets. Honesty isn't making money any more... A huge problem. The absence of any real accountability, and admiration of hypocrisy, is what threatens us most heading into the future.
- systemvoltage 5y agoI am not convinced, do you have any sources that prove your conspiracy?
- winternett 5y agoOh No... No... Not me!... :P Not really a conspiracy theory... Just a personal opinion. These days sharing "conspiracy theories" get people banned online and worse... Just made as a statement in reply to the parent comment, but if you watch the commercials during television news, you might perhaps wonder how "Restless Leg Syndrome" became a real thing, and why there's now how conveniently there is a drug that claims to "fix it" if you're willing to sacrifice diarrhea for in exchange for the pill's implied benefits.
- taf2 5y agoAssuming this is about telnxy outages this week and their migration to cloudflare. https://status.telnyx.com/ https://status.telnyx.com/ Maybe premature for cloudflare to be declaring victory?
- BuildTheRobots 5y agoWhilst I'm a big fan of people updating status pages, copy/pasted updates really rub me up the wrong way.
- maxgashkov 5y agoI was responsible for a website (one of a many of this kind) that provided access to a niche auction platform. At some point in the beginning of 2010s it became a subject of a precisely coordinated series of timed attacks designed to disrupt bidding of one of our prominent clients in the specific auctions. It was enough to bring down the service for ~5 minutes to prevent the client from winning. Eventually we migrated behind CF and the problem was solved but I couldn't help but wonder if there are some applications for which even a few seconds disruption (I assume that's the minimum time Cloudflare needs to begin effectively mitigate the attack of this scale) will be disastrous and what could possibly be done in this case?
- iimblack 5y agoStock trading comes to mind
- toast0 5y agoIf you can't handle a few seconds disruption, you really need actually private networking. Dedicated lines (or at least dedicated wavelength on shared fiber) and redundancy and very fast failover. Volumetric udp reflection isn't really too bad to process anyway, as long as you've got the bandwidth --- fancy tricks get you from the UDP stack dropping useless packets to dropping useless packets without the UDP stack, possibly at the edge without using up nearly as much internal bandwidth. Where it gets pretty hard to manage would be application level bursts, IMHO.