*http://tinyurl.com/z93p7m7 <http://tinyurl.com/z93p7m7>*

*Amid major internet outages, downed websites have lessons to learn*

When the internet fails you, have a backup plan.

[image: Description: Zack Whittaker]

By Zack Whittaker <http://www.zdnet.com/meet-the-team/us/zack-whittaker/>
for Zero Day <http://www.zdnet.com/blog/security/> | October 21, 2016

Just when everything was getting back to normal, Dyn was hit with a second
major cyberattack, knocking off dozens of high-profile websites from the
web.

Dyn's managed domain name service was hit by a massive flood of web traffic
<http://www.zdnet.com/article/dyn-a-managed-dns-service-hit-with-attack-popular-sites-see-performance-issues/>
earlier this morning that left much of the US eastern seaboard unable to
access Twitter, Reddit, and Spotify -- just to name a few.

As of the time of writing, the company was investigating and mitigating
"several" distributed denial-of-service (DDoS) against its infrastructure.

For now, exactly what's happening remains a mystery.

Some have pointed the finger of blame at state-sponsored actors.
Sister-site CBS News confirmed that Homeland Security was aware of the
attack
<http://www.cbsnews.com/news/internet-disrupted-dyn-hit-by-ddos-cyberattack/>
and is "investigating all potential causes." Others are pointing to a
resurgence of botnet activity, which has been surging in recent weeks
<http://www.zdnet.com/article/krebs-on-security-booted-off-akamai-network-after-ddos-attack-proves-pricey/>
thanks to the Mirai malware
<http://www.zdnet.com/article/source-code-of-mirai-botnet-responsible-for-krebs-on-security-ddos-released-online/>
infecting millions of smart home and internet-connected devices.

It could be days, if not weeks, before we know more about what happened.

The elephant in the room is that this probably shouldn't have happened. At
very least there's a lot to learn already about the frailty of the internet
DNS system, and the lack of failsafes and backups for websites and tech
companies that rely on outsourced DNS service providers.

"It's also a reminder of one risk of relying on multi-tenant service
providers, be they DNS, or a variety of many other managed cloud service
providers," said Steve Grobman, chief technology officer at Intel Security.

Grobman warned that because this attack worked, it can be exploited again.

"Given how much of our connected world must increasingly rely upon such
cloud service providers, we should expect more such disruptions," he said.
"We must place a premium of service providers that can present backup,
failover, and enhance security capabilities allowing them to sustain and
deflect such attacks."

And that's key, because even though Dyn is under attack, it's the sites and
services that rely on its infrastructure who should rethink their own "in
case of emergency" failsafes. It may only be the east coast affected but
lost traffic means lost revenue.

Carl Levine, senior technical evangelist for NS1, another major managed DNS
provider, said that the size and scale of recent attacks "has far exceeded
what the industry thought was the upper end of the spectrum."

That's taken some by surprise. In the past year, some of the largest
reported flooding attacks were in the 600 Gbps range, according to sources
speaking last year
<http://www.zdnet.com/article/tango-down-bbc-was-this-the-largest-ddos-web-attack/>.
Now they're looking at over 1.1 Tbps in size -- and larger in some cases
<https://www.us-cert.gov/ncas/alerts/TA16-288A>.

It may be why Dyn hasn't fended off the attackers as quickly as it could.

"Large companies need to constantly upgrade their flood defenses. Some
approaches that worked just a few years ago are now basically useless,"
said Kevin Curran, senior member with IEEE.

"Newer DDoS attacks change their profile much quicker so it becomes more
and more difficult to simply identify which packet requests are nefarious,"
he said.

As these flood attacks get more advanced, the buck stops with the websites
and services that appear to be offline -- even if they're open for business
to the rest of the world.

Levine and Grobman both recommend redundant DNS services in the event of an
infrastructure attack. If your infrastructure fails, you swap out the old
with the new -- in reality, that's easier when it comes to outsourced DNS
providers and networking infrastructure.

And there's your lesson: be nimble in the face of an attack.




------------------------------
[image: Avast logo] <https://www.avast.com/antivirus>

This email has been checked for viruses by Avast antivirus software.
www.avast.com <https://www.avast.com/antivirus>



__._,_.___
------------------------------
Posted by: "Beowulf" <[email protected]>
------------------------------


Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmZTdsdW9pBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0NzcwNzk0NzU->


[image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlcHJsaGo0BF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQ3NzA3OTQ3Ng-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to