Update: Spamhaus hit by biggest-ever DDoS attacks
DDoS traffic of up to 300Gbps has been directed at anti-spam site
Computerworld - Anti-spam service Spamhaus has been hit with what several security firms today described as the largest distributed denial of service (DDoS) attacks ever seen.
Some of the attacks have generated so much DDoS traffic that they actually slowed down sections of the Internet for brief periods of time, according to the firms.
Matthew Prince, CEO of CloudFlare, a San Francisco-based firm that has been helping Spamhaus over the past few days, today said that the attacks have been going on since March 19 and have generated up to 300Gbps of DDoS traffic.
That's about three times bigger than the biggest DDoS attacks seen so far and several magnitudes greater than the 4Gbps to 10Gbps of traffic generated by typical DDoS attacks.
"We haven't seen anything larger than this publicly," Prince said. "Its hard to get an attack this large, because what you end up doing is congesting [portions of the Internet]," he said,
Spamhaus did not respond immediately to a request for comment. However, according to The New York Times, the attacks against the Geneva-based company began after the anti-spam service added Dutch hosting provider Cyberbunker to its global blacklist.
Cyberbunker, a hosting company that operates out of an abandoned NATO bunker in the Netherlands, is known for hosting an eclectic collection of websites -- some of which are thought to be major spammers. The company prides itself on being willing to host almost any website, except those involved with terrorism and child pornography.
The company has done little to hide its dislike for Spamhaus, which it has characterized as a bully on its website. The Times quoted an alleged spokesman for the attackers as saying that Cyberbunker was retaliating because Spamhaus had abused its influence on the Internet.
According to Prince, the DDoS attacks against Spamhaus started off being fairly typical in bandwidth, but quickly grew much bigger. Between March 19 and March 22, the DDoS attacks went from 10Gbps of traffic to over 90Gbps.
When that wasn't enough to knock Spamhaus offline, the attackers changed tactics and began going after CloudFlare's upstream service providers. "As the attacks have increased, we've seen congestion across several major Tier 1s, primarily in Europe where most of the attacks were concentrated," he said.
In DDoS attacks, perpetrators typically try to take down a target network by inundating it with useless traffic. The traffic is usually generated using large botnets of compromised computers.
With Spamhaus, the attackers employed a well-known, but infrequently used, method known as a DNS reflection attack to generate the massive streams of DDoS traffic seen over the past few days, Prince noted.
- New docs show DHS was more worried about critical infrastructure flaw in '07 than it let on
- Needed: Breach detection correction
- Evan Schuman: Resurrection of Full Disclosure mailing list is great news, if you're not a cyberthief
- Cyberattacks could paralyze U.S., former defense chief warns
- Syrian Electronic Army shanghais Microsoft's Twitter account, blog
- Is French outrage against U.S. spying misplaced?
- Lawmakers seek answers on Obamacare Data Hub security
- China-based hacking group behind hundreds of attacks on U.S. companies
- How to Prepare for a Potential Syrian Counterattack on the U.S. Power Grid
- New York Times site outage caused by attack on domain registrar, company says
- Transforming Information Security: Future-Proofing Processes This report provides a valuable set of recommendations from 19 of the world'd leading security officers to help organizations build security strategies for...
- The Evolution of Corporate Cyberthreats Cybercriminals are creating and deploying new threats every day that are more destructive than ever before. While you may have more people devoted...
- 3 Questions to Ask Your DNS Host about Lowering DDoS Risks Neustar has had wide-ranging conversations with clients wanting to know how they can optimize protection as DDoS attacks increase in frequency and size.
- The Danger Deepens: 2014 Neustar Annual DDoS Attacks and Impact Report This report compares DDoS findings from 2013 to 2012, based on a survey of 440 North American companies, including 139 businesses delivering technology...
- Establish Cyber Resiliency: Developing a Continuous Response Architecture Many enterprises fail to proactively prepare the battlefield for a data breach by only leveraging outdated techniques that focus on the perimeter or...
- An Incident Response Playbook: From Monitoring to Operations As cyber-attacks grow more sophisticated, many organizations are investing more into incident detection and response capabilities. In this webcast, learn how to develop... All Cybercrime and Hacking White Papers | Webcasts