The Broadband Guide
SG
search advanced

DDoS Attack Hits 400 Gbit/s, Breaks Record

2014-02-12 10:01 by
Tags: ,

 

The infrastructure of web security company CloudFlare has been attacked on Monday evening by what appears to be one of the largest DDoS (distributed denial-of-service) attacks ever. The target was a CloudFlare customer, and the attack appears to have been just shy of 400Gbps, Matthew Prince, the company's CEO, said.

"Very big NTP reflection attack hitting us right now. Appears to be bigger than the #Spamhaus attack from last year. Mitigating," Price said in a tweet. "Someone's got a big, new cannon. Start of ugly things to come," he wrote in a follow-up tweet.

The latest attack leveraged a technique known as a Network Time Protocol (NTP) reflection. It's an attack that the U.S. Computer Emergency Readiness Team (US-CERT), which is part of the U.S. Department of Homeland Security, has been warning against since January.

"Due to the spoofed source address, when the NTP server sends the response it is sent instead to the victim," CERT warned. "Because the size of the response is typically considerably larger than the request, the attacker is able to amplify the volume of traffic directed at the victim. Because the responses are legitimate data coming from valid servers, it is especially difficult to block these types of attacks," US-CERT said in its January advisory, which included suggestions on how administrators could mitigate vulnerability.

The US-CERT recommends updating NTP servers to at least ntpd (Network Time Protocol daemon) version 4.2.7, which addresses the monlist issue by default. Older versions need to be manually configured to restrict the functionality.

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About