Email this article   Print article 


Cyber Monday: Can The Internet Be Taken Down By Massive DDoS Attacks?

By Ken Presti
November 26, 2012    6:30 PM ET

Page 1 of 2

The recent string of DDoS attacks against banks and other financial institutions has renewed discussions among service providers on how to protect networks in an era when bandwidth is continually on the increase and toolkits to assist cyber criminals are becoming increasingly pervasive and complex.

This issue was discussed at length in a blog post by Carlos Morales, vice president of sales engineering and operations of Arbor Networks, a Chelmsford, Mass.-based security company.

"Attackers are not fearing the authorities," Morales told CRN. "The tools are developing at a fast pace. Attackers are becoming a lot more brazen, and people, in general, are becoming a lot more aware of DDoS attacks and their growing size and scope.

[Related: Cyber Monday: How Secure Companies Are Keeping Their Websites Safe]

"What's changing is the amount of bandwidth available to everybody, whether it's made available through fiber-to-the-home or anything else that delivers tons of megabits to the desktop," Morales continued. "Plus the power of CPU and memory-based processing is being delivered so cheaply that you can generate a whole lot of traffic over the available bandwidth. So the superhighways of the Internet have become so large it is now quite possible to bring in intermediate-sized service provider to its knees, if someone chose to do so."

According to Morales, most enterprise and government data centers have no more than 10 Gbps worth of upstream bandwidth, but the attacks are frequently becoming larger. According to his company's statistical engine, the largest bandwidth attacks measured in 2011 and 2012 were 101.4 Gbps and 100.8 Gbps respectively, which is more than enough to cause serious disruptions.

"Over the next couple of years, you will see end-user hosts with 100 megabits per second of bandwidth available on average," he predicted. "If you get 100 of these machines functioning within a botnet, that'll take down a lot of different operators. Then you look at 10,000 host botnets, which is not uncommon. We're seeing botnets in the millions now. At this point, you are reaching a level that's going to impact the traffic of some of the largest backbone carriers in the world. They have that kind of capacity, but they don't necessarily have that kind of spare capacity. So it wouldn't take down the Internet for life but would cause an unprecedented amount of congestion. It would basically be Internet gridlock."

Morales speculated that attackers may choose to make their move during a Cyber Monday, an election day or any other time when Internet resources are already in high demand. He also noted that size is not the only means by which such an attack can be effective. "Application layer attacks, IP protocol attacks, connection attacks and other stealthy attack methods" can also be instrumental in having the same effects.

NEXT: Focus On Defense In Depth

1 | 2 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...