bk99.de entertain the web since 1997

620 Gbit/s: Mirai announces a new class of DDoS

Summary

Brian Krebs documents a DDoS attack that was exceptional at the time and whose direct traffic floods pointed to a large botnet of compromised IoT devices. The attack began on the evening of 20 September 2016. After analysis, Akamai put the peak load at around 620 Gbit/s.

Ideas

  • Direct floods require many actually compromised devices instead of a few amplifiers.
  • GRE traffic made up an unusually large share of the attack.
  • Routers, cameras and video recorders together formed a globally distributed attack surface.
  • Weak or hard-coded passwords allowed devices to be taken over en masse.
  • DDoS can economically censor journalism through infrastructure costs.
  • Attacks on single targets put a strain on shared protection infrastructure.

Insights

  • Device security increasingly determines the resilience of completely unrelated services.
  • New attack sizes can economically devalue protection models that used to be sufficient.
  • The traffic pattern and protocol mix reveal the architecture of a botnet.

Quotes

  • Someone has a botnet with capabilities we haven’t seen before. – Martin McKeay

Habits

  • Krebs publishes measurements and visibly corrects them as soon as Akamai refines its analysis.

Facts

  • Akamai’s largest previous case was 363 Gbit/s.
  • The main methods observed needed no DNS reflection or other amplification.

References

Critique

  • The first assessment could not yet determine the botnet, operator and motive beyond doubt.
  • Record comparisons depend on the measuring point, duration and chosen traffic metric.

Remarks

  • The article captures the moment before Mirai’s source code became public.
  • The attack was probably connected with Krebs’ research into the DDoS service vDOS.

Recommendations

  • Plan DDoS protection by packet rate, bit rate and protocol mix.
  • Remove default credentials on every internet-connected device.
  • Agree escalation paths and capacity limits with upstream protection providers.

Read the original article

Search the Web Archive