
Sleuthing Out the DoS Attacks
by Declan McCullagh
12:05 p.m. 14.Feb.2000 PST
Alan Hannan had just heard a lecture about distributed denial of service attacks when his cell phone rang.
The timing was eerie. On the other end of the call was a harried customer with an ominous warning: There were problems on the network connecting Yahoo's main Web site with the rest of the world.
Read more in E-Biz
Read more in Executive Summary
Read more Technology news
Everybody's got issues in Politics
Infostructure strengthens your backbone
Hannan is a vice president at Global Crossing, which owns that network, and his brief cell phone conversation in the hallway of the North American Network Operators' Group convention provided few clues about the extent of the turmoil. It certainly didn't prepare him for the dizzying size of the attack that crippled the world's most popular Web site for about three hours last week, and foreshadowed a wave of similar assaults.
The chief irony might be that the questions of the world's press were directed at the people least qualifed to respond. Reporters spent most of the week hounding the FBI, Justice Department, and President Clinton for details. During a press conference last week, all Attorney General Janet Reno could say was, "We are not aware of the motives behind these attacks."
Instead, network engineers were the detectives who unearthed the most important clues. Administrators at Stanford University and the University of California at Santa Barbara reported that their systems were co-opted in the denial of service attacks, which lured a stampede of reporters to their campuses. "They went through our labs and the press has been asking the attendants stupid questions. We just smile and nod," said one amused UCSB student.
There's a very good reason why the Internet's technicians have become not just guardians of their customers' Web sites, but amateur sleuths as well: They have more collective experience than anyone else in thwarting online mischief-making.
"The FBI is basically relying on the providers to figure it out," says an executive at one network provider that was the target of an DoS attack last week.
To veteran networking gurus, the attacks were more high-profile than usual, but hardly unprecedented. Internet relay chat servers have been the subject of smaller DoS attempts since at least 1996, and automated "smurf" tools like trinoo and TFN have been available since last summer.
"We were concerned but not overly so," said Kelly Cooper, the Cambridge-based Internet security officer for GTE Internetworking. "Smurf attacks are something we're very familiar with and we're pretty good at handling them.... We see smurf attacks anywhere from once or twice a week to only a couple a month."
GTE offers connectivity to ZDNet, eTrade, and CNN, and a GTE customer provides a link to Amazon. All four companies were victims of smurf attacks last week, but GTE said only one assault came close to clogging an OC-3 connection, a fiber optic link that carries data at 155 Mbps. "We had to get creative with our filters," Cooper said.
Because U.S. system administrators have been patching security holes that permit DoS attacks, vandals are turning to overseas computers. "We did see a fair amount of the ZDNet traffic coming from Europe," said Cooper. "We stopped a lot of traffic in the D.C. area [where GTE's European links connect] to stop it from impacting the Eastern corridor."
1 of 2
Next
>>
Have a comment on this article? Send it
Email this to a friend.
Fax
this from your computer for free
|