viralamo

Menu
  • Technology
  • Science
  • Money
  • Culturs
  • Trending
  • Video

Subscribe To Our Website To Receive The Last Stories

Join Us Now For Free
Home
Technology
Tsunami of junk traffic that broke DDoS records delivered by tiniest of botnets
Technology

Tsunami of junk traffic that broke DDoS records delivered by tiniest of botnets

16/06/2022

Tsunami of junk traffic that broke DDoS records delivered by tiniest of botnets

Aurich Lawson | Getty Images

A massive flood of malicious traffic that recently set a new distributed denial-of-service record came from an unlikely source. A botnet of just 5,000 devices was responsible as extortionists and vandals continue to develop ever more powerful attacks to knock sites offline, security researchers said.

The DDoS delivered 26 million HTTPS requests per second, breaking the previous record of 15.3 million requests for that protocol set only seven weeks ago, Cloudflare Product Manager ​​Omer Yoachimik reported. Unlike more common DDoS payloads such as HTTP, SYN, or SYN-ACK packets, malicious HTTPS requests require considerably more computing resources for the attacker to deliver and for the defender or victim to absorb.

4,000 times stronger

“We’ve seen very large attacks in the past over (unencrypted) HTTP, but this attack stands out because of the resources it required at its scale,” Yoachimik wrote.

Cloudflare

The burst lasted less than 30 seconds and generated more than 212 million HTTPS requests from more than 1,500 networks in 121 countries, with Indonesia, the United States, Brazil, and Russia topping the list. The top networks used included French-based OVH (Autonomous System Number 16276), the Indonesian Telkomnet (ASN 7713), the US-based iboss (ASN 137922), and the Libyan Ajeel (ASN 37284). About 3 percent of the attack came through Tor nodes.

Cloudflare

Cloudflare

As was the case with the previous 15.3 million HTTPS requests-per-second attack, the new one originated mainly on devices from cloud service providers. The servers and virtual machines available from these providers are considerably more powerful than compromised computers and IoT devices connected to residential ISPs, which are the more common source of DDoSes.

Advertisement

Yoachimik wrote:

The 26M rps DDoS attack originated from a small but powerful botnet of 5,067 devices. On average, each node generated approximately 5,200 rps at peak. To contrast the size of this botnet, we’ve been tracking another much larger but less powerful botnet of over 730,000 devices. The latter, larger botnet wasn’t able to generate more than one million requests per second, i.e. roughly 1.3 requests per second on average per device. Putting it plainly, this botnet was, on average, 4,000 times stronger due to its use of virtual machines and servers.

In some cases, DDoSers combine their use of cloud-based devices with other techniques to make their attacks more potent. In the 15.3 million HTTPS request-per-second DDoS from earlier this year, for example, Cloudflare uncovered evidence that the threat actors may have exploited a critical vulnerability. This exploit allowed them to bypass authentication in a wide range of Java-based applications used inside the cloud environments running their attack devices.

DDoS attacks can be measured in several ways, including by the volume of data, the number of packets, or the number of requests sent each second. The other current records are 3.4 terabits per second for volumetric DDoSes—which attempt to consume all bandwidth available to the target—and 809 million packets per second. The 26 million HTTPS requests per second break the previous 17.2 million requests per second record set in 2020. Not only did that earlier attack deliver fewer packets than the new record, but it also relied on HTTP, which isn’t as potent as HTTPS.

The Cloudflare product manager said that his company automatically detected and mitigated the attack against the customer, which was using Cloudflare’s free service.

Source link

Share
Tweet
Pinterest
Linkedin
Stumble
Google+
Email
Prev Article
Next Article

Related Articles

Cordio and Rambam Hospital will trial AI that detects coronavirus cases from speech samples
Cordio Medical today announced that it will begin a clinical …

Cordio and Rambam Hospital will trial AI that detects coronavirus cases from speech samples

The DeanBeat: Apple v. Epic — a briefing on the antitrust arguments and interesting facts
We’re at a huge moment in tech and antitrust history …

The DeanBeat: Apple v. Epic — a briefing on the antitrust arguments and interesting facts

Leave a Reply Cancel reply

Find us on Facebook

Related Posts

  • Almighty: Kill Your Gods is a co-op action-RPG about slaying your deities
    Almighty: Kill Your Gods is a co-op …
    14/06/2020
  • Razer Book 13 laptop is a productivity laptop from a gaming brand
    Razer Book 13 laptop is a productivity …
    05/11/2020
  • The DeanBeat: Gaming mental health conference encourages men to seek help
    The DeanBeat: Gaming mental health conference encourages …
    21/08/2020
  • Cloud gaming is going to make customer support more complicated
    Cloud gaming is going to make customer …
    23/11/2019
  • Is the office dead? What COVID-19 means for the future of property tech
    Is the office dead? What COVID-19 means …
    14/06/2020

Popular Posts

  • 10 Shocking and Surprising Facts About the …
    25/06/2022 0
  • US college VPN credentials for sale on Russian crime forums, FBI says
    US college VPN credentials for sale on …
    27/05/2022 0
  • 10 Cheap Foods That Will Make You …
    28/05/2022 0
  • 10 Origin Stories of Favorite Classic Sitcoms …
    28/05/2022 0
  • Top 10 Historical Musicals That Aren’t “Hamilton” …
    29/05/2022 0

viralamo

Pages

  • Contact Us
  • Privacy Policy
Copyright © 2022 viralamo
Theme by MyThemeShop.com

Ad Blocker Detected

Our website is made possible by displaying online advertisements to our visitors. Please consider supporting us by disabling your ad blocker.

Refresh