620 Gbit/s: Mirai announces a new class of DDoS
Summary
Brian Krebs documents a DDoS attack that was exceptional at the time and whose direct traffic floods pointed to a large botnet of compromised IoT devices. The attack began on the evening of 20 September 2016. After analysis, Akamai put the peak load at around 620 Gbit/s.
Ideas
- Direct floods require many actually compromised devices instead of a few amplifiers.
- GRE traffic made up an unusually large share of the attack.
- Routers, cameras and video recorders together formed a globally distributed attack surface.
- Weak or hard-coded passwords allowed devices to be taken over en masse.
- DDoS can economically censor journalism through infrastructure costs.
- Attacks on single targets put a strain on shared protection infrastructure.
Insights
- Device security increasingly determines the resilience of completely unrelated services.
- New attack sizes can economically devalue protection models that used to be sufficient.
- The traffic pattern and protocol mix reveal the architecture of a botnet.
Quotes
Someone has a botnet with capabilities we haven’t seen before.
– Martin McKeay
Habits
- Krebs publishes measurements and visibly corrects them as soon as Akamai refines its analysis.
Facts
- Akamai’s largest previous case was 363 Gbit/s.
- The main methods observed needed no DNS reflection or other amplification.
References
- Brian Krebs: KrebsOnSecurity Hit With Record DDoS
- Akamai: protection and analysis provider at the time.
- Mirai: the IoT botnet attributed later.
Critique
- The first assessment could not yet determine the botnet, operator and motive beyond doubt.
- Record comparisons depend on the measuring point, duration and chosen traffic metric.
Remarks
- The article captures the moment before Mirai’s source code became public.
- The attack was probably connected with Krebs’ research into the DDoS service vDOS.
Recommendations
- Plan DDoS protection by packet rate, bit rate and protocol mix.
- Remove default credentials on every internet-connected device.
- Agree escalation paths and capacity limits with upstream protection providers.
Links to the original source and the Web Archive open in a new tab.