Comment: Poor configuration amplifies DoS danger

Hackers aiming to disable root DNS servers on the Web could be more easily thwarted if networks left fewer avenues of attack open, says Lem Bingley

Written by Lem Bingley, IT Week

On 21 October at 9pm, somebody initiated an hour-long attack on the foundations of the Internet. The distributed denial-of-service (DDoS) attack troubled or disabled nine of the 13 root DNS servers - the core of the system supporting memorable Net addresses in place of raw IP numbers.

If the attack had crippled all the DNS roots, the result would have been insidious rather than catastrophic. DNS caches worldwide would have grown stale, with increasing failure rates. "[If] you take the root servers out, you don't know how long you can work without them," said Alan Paller, director of research at security body the Sans Institute.

It doesn't take a genius to organise a DDoS attack. More damaging but much more difficult would be to garble the root DNS data. On 17 July 1997, information on seven of the then nine root servers was corrupted by accident, and was left unfixed for four hours. Widespread routing problems quickly resulted.

Of course, the root server operators put a lot of effort into securing systems against would-be garblers. But while a DDoS attack is easier to set up than a successful database hack, defending a system against DDoS attacks is arguably a lot harder than keeping out hackers.

That's because the DDoS idea is to overwhelm legitimate lines of communication. It can be tough to cut off attacking traffic without locking out every other user. The Internet Engineering Task Force has pondered the problem, and offered a solution in RFC2827. This recognises that attacks have to be deflected before they reach the victim.

In the root server attack, the hacker used a "Smurf" technique, or something similar, relying on a flood of ICMP "ping" messages.

To create a Smurf attack, the hacker amasses an army of hacked machines - called drones, slaves or zombies - owned by others around the Net. Each is planted with software, set to launch the attack at a pre-arranged time. Once triggered, drones send out streams of ICMP traffic to IP broadcast relays - routers that will pass on one message to several other addresses. This tactic multiplies the number of machines involved in the eventual attack. According to Netscan.org, there are currently more than 25,000 such "amplifiers" available as a result of poor network administration.

Each ICMP packet is sent out with a forged source address - in this case the address of a DNS server. Every machine that receives the broadcast therefore replies to a DNS server, overwhelming the servers with irrelevant interrupts.

As RFC2827 notes, forged addresses are detectable only in the earliest stages of attack. ISPs are aware of the range of IP addresses under their control, so they could drop all outgoing packets that claim a source address outside the correct range. Similarly, corporate firewalls should be set to detect and block packets leaving the network that claim a source address outside it.

Unfortunately, these measures are not widely implemented due to a mixture of denial, complacency and cost constraints. Cost, really, should not be the governing factor. Ask your ISP if it implements RFC2827 and if not, why not. And if you haven't already done so, set up outgoing address filtering at your firewall.

Have your say: contact IT Week

More IT Week Comments

Tags:

reader comments

related articles

Firms leave firewall gaps

Poorly configured firewalls make distributed denial-of-service attacks too easy for hackers 04 Nov 2002

 

FBI investigates major web slowdown

Global internet servers crippled in massive DoS attack 23 Oct 2002

Reported DDoS attacks double

High-profile websites affected 22 Aug 2002

Third of UK businesses at DDoS risk

Flood of attacks will cost £54m this year alone 24 Apr 2002

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation