Akamai now says it was targeted by DDoS attack
It had earlier blamed a larger, global attack for yesterday's outage
June 16, 2004 12:00 PM ETComputerworld -
Akamai Technologies Inc. said today that problems it experienced yesterday morning were caused by a "sophisticated" and large-scale attack aimed at specific Akamai customers, not by a global attack (see story).
In a statement released this morning, Akamai also said the impact of the distributed denial-of-service (DDoS) attack had been overstated. According to Akamai, less than 1% of the company's 1,100 customers "had a significant impact affecting more than 20% of their users."
Overall, only 4% of Cambridge, Mass.-based Akamai's customer base was affected by the Domain Name System problems, with "noticeable impact" being restricted to 2%.
The attack "resulted in delays in DNS name resolutions and, in some cases, timed-out DNS requests," the company said.
The company detected the attack via its automated monitoring systems and worked with several network partners around the world to fix it, Akamai said. Federal law enforcement agencies are now investigating the incident.
Despite the slowdown, "the attack did not cause an outage in Akamai services, as Akamai continued to serve both DNS requests and Web site content for customers throughout the period of the attack," Akamai said.
Several large customers of Akamai suffered performance degradations yesterday morning as a result of the problems related to Akamai's DNS systems. Keynote Systems Inc., a San Mateo, Calif.-based third-party Web site performance measurement firm, said that in some cases, availability of affected sites dropped to near zero for a brief period.
Microsoft Corp., Yahoo Inc. and Google Inc. yesterday confirmed performance issues on their Web sites as a result of the attack, but they didn't elaborate.
"The attack appears to have been very targeted at Akamai, and we have observed no scatter at this point," said Johannes Ullrich, chief technology officer at the Bethesda, Md.-based SANS Institute's Internet Storm Center.
The sheer size of Akamai's Content Delivery Network (CDN), which comprises thousands of globally distributed servers, initially made it seem unlikely the company was the victim of a DDoS attack, Ullrich said. "An attacker would require not only a very large number of zombie systems for such an attack, but they would also have to be placed at the right locations" to be effective, Ullrich said.
The latest statement from Akamai indicates that it wasn't the CDN that was targeted, but Akamai's enhanced DNS service, which consists of only a few dozen servers, Ullrich said. "Unlike the CDN, these systems will only act as backup DNS servers and not serve any Web content. Given that we have observed botnets with hundreds of thousands of hosts in
Additional Resources


White Papers & Webcasts
Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
