I had a chat yesterday with someone who is on the
front lines in the fight against cyber-extortion. Barrett Lyon is an
expert on building the infrastructure and defenses to survive
Distributed Denial of Service attacks. His story is fascinating. You
can read more about it in the New Yorker.
Traditional DDoS of course is when an attacker uses thousands of centrally controlled zombie machines Barrett raises the specter of a new generation of zombies.
to direct millions of packets at a single destination. Most web servers
shrivel up and die when subjected to that much attention. According to
Barrett even the upstream infrastructure cannot withstand some of these
attacks. The firewalls, routers, sometimes even the ISP go off line. A
recent new technique is for the zombies to all perform DNS look-ups
causing a failure of the DNS server for the target to die, effectively
taking down a site without even hitting it directly.
But in the podcast
I did with Barrett yesterday he raises the specter of a new generation
of zombies, Linux zombies, being used to launch attacks against
targets. He says in a recent battle he had to defend a site that was
under attack from a Japanese hacker who had been hired by someone to
take out their competitor, Barrett's client.
8:16:40 PM PermaLink /
|