From the article: "The assault has flooded Krebs' site with more than 620 Gbps per second of traffic — nearly double what Akamai has seen in the past."
If it takes a mere 620 G-bit to screw Akamai, then they're obviously not much of a content distribution platform. I only need a few thousand compromised machines in the right countries to run 5+ T-bit scale attacks. This isn't the 90s any more, and Akamai has no reason to not have improved bandwidth capabilities, unless they're doing like the Telecoms companies by saving that money and never using it to improve their own infrastructure.
I'm going to call shenanigans. Do a quick google for the largest DDoS attacks on record, and this is one of them if not the largest. Pulling from places like Arbor, and their yearly reports, the largest previously seen were ~500Gbps. I seriously doubt you and "a few thousand" machines can magically be 8-10x stronger than the largest attacks on record.
I would love to see some sources that ANYONE can get close to that number. Short of the NSA bringing its full power to target a specific pipe, I don't think we're there yet.
I'm willing to bet you're not including compromised backbone routers and symmetrical gigabit-fiber connections. There's enough of the latter in the USA, to homes, to do that much and then some.
But what you're arguing isn't reality. Show me a source article where someone has compromised a backbone router, and then used it for DDoS. This is almost exactly what I was addressing when I said "Unless you use the power of the NSA to target a single pipe." Even in a hypothetical scenario where you have gotten your hands on one: How long do you think companies are going to let their half million dollar router be consumed for a DDoS before they take notice?
I think its pretty obvious you don't understand how internet traffic really flows, when you think "all I have to do is compromise 600 pc's with a Gb connection and I can launch a 600Gbps DDoS."
"I think its pretty obvious you don't understand how internet traffic really flows, when you think "all I have to do is compromise 600 pc's with a Gb connection and I can launch a 600Gbps DDoS."
I've been doing networking for 26 years. One of my largest jobs was mitigating Slashdot effect for two high-profile sites. I know very well how a DISTRIBUTED denial of service attack works, can work, and have done many of my own in checking security measures for those whom I consult. Compromising backbone routers is actually fairly simple. Too much reliance upon software stacks and not enough reliance upon sound hardware logic design that's proofed against attack in the first place.
>Compromising backbone routers is actually fairly simple.
Yes, the state of security on routers, even some rather large routers is embarrassing, but when routers have business-critical amounts of bandwidth? they are attached to pagers.
Regardless of what you think of us, the folks attached to the pager, when you start messing with big important routers, at least if you mess with them to the point where it interferes with the business needs of the people who are paying money for said routers? you are going to wake us up. You are going to have a really hard time using these routers for much more than an hour before there is someone on-site trying to fix it.
Sure, the state of security for monitoring is also abysmal. if you wanted to put in per-router effort, I'm sure you could take my pager offline when you take my router offline. but customers will notice, customers will complain, and at almost every place where I've been on pager, there have been alternate routes to get to me. Hell, I once woke up to a very excited office manager shouting and pounding on my door because the whole office was down, I was sleeping in, and my pager wasn't charged. It freaked the hell out of my roommates; the office manager had a thick accent, and was built like someone out of a HK action film. They thought for sure I was gonna get messed up because I owed someone money.
But yeah, I mean, sure, with sufficient subtlety, you could use a small amount of the available bandwidth on a poorly-monitored backbone router. And a lot of them are poorly monitored. But my point is just that once you start using them hard enough that it interferes with the business needs of the people paying for them? Regardless of how terrible the monitoring system is, people will notice. Security isn't the only thing that is embarrassing on those routers; businesses are used to this shit failing, and even if most people don't know what to do beyond turning it off and back on, when there are dollars involved, there are procedures for getting someone who does know how to fix it on-site.
Especially since Akamai has placed themselves in the cdn market as "WE cost more, but we are the best there is." Hell, a ton of other "cdns" are merely reselling Akamai with friendlier contracts and features.
I was impressed by that number too, but after reading your comment it seems awfully small. In 2016, what kind of attack do you expect CDN like Akamai to handle?
Don't worry about his comment. He has no idea what he is claiming. These recent attacks are labeled record breaking because they actually are. This one at 620Gbps and the recent ~1Tbps against OVH are the biggest in history, and still 5x less than what he claims.
Of course we will get there sooner than any of us in infosec want, but he is almost an order of magnitude off of what realistic threats look like.
Almost an order of magnitude? You obviously don't know what that means. I'm at half a magnitude of order off by your supposed words (protip: An order of magnitude meas you add a zero to the end of the number you're using,) and you know not much about CDNs if you don't think that multiple terabits of traffic are flowing through Akamai every second already.
Currently, I do the physical networking builds for a mental health company. We're already deploying 100 G-bit in these offices as primary connection trunks, because a lot of these services will be done remotely over video and audio.
I could open up a 20,000 user Camfrog Video Cluster chat room and could saturate a T-bit connection link just like that the second it's half-full. Have you ever used (let alone seen)a T-bit scale program before? Camfrog's been out for over a decade.
Tangent: orders of magnitude are exponential - if you want to say "half an order if magnitude" you have to do it along the exponential curve. 5x is about 0.7 orders of magnitude; half an order of magnitude is a bit over 3x.
Orders of Magnitude, n; a class in a system of classification determined by size, each class being a number of times (usually ten) greater or smaller than the one before."
There are very few disciplines where OOM is done by exponential form (astronomy/star magnitude being one of them.) It's almost always base-ten. When you use electrical conductivity in mineral identification, you're always multiplying a number by ten multiple times over. The effect of that? You either add or remove an equal amount of zeros to the original number being multiplied.
Chattanooga has symmetrical G-bit fiber to the home. 5,000 Chat-town residents got uppity, think of what would happen to Akamai if they couldn't deal with 600-ish G-bit.
It is, as it's a municipal network and not a shitty company-owned one. Designed right from the ground up from day one, much like the fiber service in Sandy, Oregon (300/300 for $40, no limits, caps, throttling, nada.)
Sounds pretty epic.