Difference between revisions of "DDoS Attack"

From ICANNWiki
Jump to navigation Jump to search
(61 intermediate revisions by 4 users not shown)
Line 1: Line 1:
[[Image:UnderConstruction.png]]
+
'''Distributed Denial of Service Attacks''', or '''DDoS Attacks''', effectively flood websites or servers with traffic from many different sources in order to "make the site unavailable."<ref name="attack map">[http://www.digitalattackmap.com/understanding-ddos/ What is a DDoS Attack?], Digital Attack Map</ref> DDoS is a type of [[DoS Attacks|Denial of Service Attack (DoS Attack)]] that uses multiple sources in order to blocks users from accessing the site. It is important to remember that not all service errors are the result of attack behaviors and can occur if a website is overwhelmed by non-malicious traffic as well.<ref>[http://www.us-cert.gov/ncas/tips/ST04-015 Security Tip (ST04-015): Understanding Denial-of-Service Attacks] (February 6, 2013), United States Department of Homeland Security</ref>
  
 +
==Public Perception==
 +
The public perception of DDoS attacks is negative. It is inconvenient to users who cannot reach their destination, and it can create major problems for the website's registrant, whether it is the website of an individual or an organization. DDoS attacks can become criminal when the attacker asks for money to stop the current attack or to prevent further attacks.<ref name="blog"/> DDoS attacks can also be used by "hacktivists" for political gain, to interrupt free speech, or in protest of perceived injustice.<ref name="attack map"/><ref name="blog"/>
  
'''DDoS''' is the acronym for '''Distributed Denial of Service.''' The [[Software Engineering Institute]] (SEI)- [[CERT]] at [[Carnegie Mellon University]] explained that the telephone system, computer system and the Domain Name System ([[DNS]]) sometimes become unusable because of intruders or hackers. For example when a hacker sent a very large amount of email to someone which can not be handled by the recipients computer disk that saves e-mail, a '''Denial of Service (DoS) attack''' will occur because the user will not be able use his or her computer until the situation is resolved. In terms of computer network, intruders send extraordinary amount of internet calls to computers that provide internet service  preventing users to get internet connection. Users whose networks are unable to use the internet services because of intrusion are victims of Distributed Denial Of Service attack.<ref>[http://www.cert.org/homeusers/ddos.html What is a Distributed Denial of Service (DDoS) Attack and What Can I Do About It?]</ref>]
+
==Outcome==
 +
The outcome of a DDoS attack is that the attacked website is unavailable or runs very slowly. The damage done by these attacks can lead to minor inconveniences, losses in consumer confidence, or large revenue losses.
  
==References==
+
==Historical Use==
{{reflist}}
+
*DDoS attacks have been used to take down or interrupt the traffic of large sites, making them inaccessible.<ref name=Weiss>[http://www.esecurityplanet.com/network-security/how-to-prevent-dos-attacks.html How to Prevent DoS Attacks] by Aaron Weiss (July 2, 2012), eSecurity Planet</ref><ref>[http://blog.icann.org/2013/04/do-more-to-prevent-dns-ddos-attacks/ Do More to Prevent DNS DDoS Attacks] by Dave Piscitello (April 3, 2013), Internet Corporation for Assigned Names and Numbers (ICANN)</ref> These planned attacks can be committed for political, social, and/or illegal purposes.<ref name="blog"/> Unlike regular DoS attacks, DDoS attacks use multiple computers to attack their victims which often makes the attack harder to stop.<ref name=Weiss/> [[Botnet Attacks|Botnets]], or networks of computers controlled by hackers, are often used in DDoS attacks.<ref>[http://www.prolexic.com/knowledge-center-what-is-ddos-denial-of-service.html What is DDoS denial of service? What everyone needs to know about DDoS], Prolexic</ref>
 +
 
 +
*Four types of DDoS attacks include:<ref name="attack map"/>
 +
#TCP Connection Attacks: attempting "to use up all the available connections to infrastructure devices"<ref name="attack map"/>
 +
#Volumetric Attacks: attempting to use large amounts of bandwidth
 +
#Fragmentation Attacks: sending so many TCP or UDP fragments that the target cannot assemble them, which slows the system
 +
#Application Attacks: trying to flood one aspect or application on a given site
 +
 
 +
*A DDoS attack can be bought or traded as a service. For example, an attack that lasts a week can be purchased for $150,<ref name="attack map"/> while an attack that lasts 1 hour can be bought for $30-70.<ref>[http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-russian-underground-101.pdf Russian Underground 101] (PDF) by Max Goncharov, TrendMicro.com</ref>
 +
 
 +
*In addition to causing service errors, DDoS attacks can also be used to commit "other cybercrimes, including data breaches or financial fraud."<ref>[https://www.networkworld.com/newsletters/techexec/2013/101113bestpractices.html?page=2 Best practices to mitigate DDoS attacks] by Linda Musthaler (January 10, 2013), Network World</ref>
  
 +
==ICANN Policy==
 +
*ICANN does not have a policy that specifically addresses DDoS attacks; however, ICANN's blog has addressed the issue of how to respond to and report a DDoS attack.<ref name="blog">[http://blog.icann.org/2013/04/how-to-report-a-ddos-attack/ How to Report a DDoS Attack] by Dave Piscitello (April 25, 2013), Internet Corporation for Assigned Names and Numbers (ICANN).</ref> If a site is under attack, the 2013 post suggests that the registrant contacts the hosting provider and internet service provider (ISP).<ref name="blog"/> If the attack was proceeded by a threat or a sum of money was demanded to stop the attack, the registrant should contact law enforcement.<ref name="blog"/>
  
 +
*ICANN's Security and Stability Advisory Committee ([[SSAC]]) also released an advisory in 2006 on DDoS attacks in relation to the DNS.<ref>[http://www.icann.org/en/groups/ssac/dns-ddos-advisory-31mar06-en.pdf SSAC Advisory SAC008: DNS Distributed Denial of Service (DDoS) Attacks] (PDF), ICANN Security and Stability Advisory Committee (SSAC)</ref>
  
 +
*ICANN's [[SSAC]] released another advisory in 2014 on DDoS attacks and how they may exploit certain security issues in the DNS.<ref name="s">[http://www.icann.org/en/groups/ssac/documents/sac-065-en.pdf SSAC Advisory on DDoS Attacks Leveraging DNS Infrastructure] (PDF), ICANN Security and Stability Advisory Committee (SSAC)</ref> For example, an attacker may use a victim's spoofed IP address to make multiple queries to an open recursive DNS server; the server will then respond by flooding the victim's computer with the unsolicited responses.<ref name="sing">[http://singapore49.icann.org/en/schedule/thu-ssac SSAC's Update Presentation at ICANN 49] (PDF and audio)</ref> DDoS attacks that utilize "DNS reflection and amplification" can have "attack data bit rates reportedly exceeding 300 gigabits per second."<ref name="sing"/> The advisory suggests that "ICANN should...facilitate an Internet-wide community effort to reduce the number of open resolvers and networks that allow network spoofing."<ref name="s"/> Additionally, rate limiting and blocking abusive queries may help reduce DDoS attacks.<ref name="sing"/> The SSAC also recommends that DNS software and systems be updated regularly to reduce DDoS vulnerability.<ref name="sing"/>
 +
**Read the [http://www.icann.org/en/groups/ssac/documents/sac-065-en.pdf SSAC's Advisory on DDoS Attacks Leveraging DNS Infrastructure]
 +
**View the [http://singapore49.icann.org/en/schedule/thu-ssac SSAC's Presentation at ICANN 49]
  
 +
==Legislation==
 +
*[[Computer Fraud and Abuse Act]] (CFAA): this act, last amended in 2008,<ref>[http://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act Computer Fraud and Abuse Act] at Wikipedia</ref> prohibits the unauthorized use of another person's computer, among other things.<ref>[https://ilt.eff.org/index.php/Computer_Fraud_and_Abuse_Act_%28CFAA%29 Computer Fraud and Abuse Act (CFAA)] at Internet Law Treatise</ref><ref>[http://us.practicallaw.com/2-508-3428 Computer Fraud and Abuse Act (CFAA)] at Practical Law, Thomson Reuters</ref> In relation to DDoS attacks, if the hacker used a botnet to perpetrate the attack, he or she could be charged under CFAA in addition to facing civil suits.<ref>[http://us.practicallaw.com/7-516-9293 Distributed Denial-of-Service (DDoS) Attack] at Practical Law, Thomson Reuters</ref> DDoS attackers can also face jail time.<ref name="naked">[http://nakedsecurity.sophos.com/2010/12/09/are-ddos-distributed-denial-of-service-attacks-against-the-law/ Are DDoS (distributed denial-of-service) attacks against the law?] by Graham Cluley (December 9, 2010), Naked Security, Sophos</ref>
 +
**Read more about the [https://ilt.eff.org/index.php/Computer_Fraud_and_Abuse_Act_%28CFAA%29 CFAA].
  
 +
*Other nations, such as the UK and Sweden, also have anti-DDoS legislature.<ref name="naked"/>
  
 +
==DNS Award==
 +
Awardees take a proactive approach to preventing DDoS attacks.
  
 +
==Additional Resources==
 +
*Review facts and watch a video explaining [http://www.digitalattackmap.com/understanding-ddos/ DDoS Attacks]
 +
*View a [http://www.digitalattackmap.com/#anim=1&color=0&country=ALL&time=16097&view=map DDoS Attack Map]
 +
*Read the [http://www.icann.org/en/groups/ssac/dns-ddos-advisory-31mar06-en.pdf SSAC's DDoS Advisory]
 +
*See [http://www.us-cert.gov/ncas/tips/ST04-015 CERT's Security Tips Page] for signs that indicate you may be experiencing a DDoS attack
 +
*View a [http://www.circleid.com/posts/20140318_what_does_a_ddos_attack_look_like/ Visualization of a DDOS Attack]
 +
*Listen to the [http://singapore49.icann.org/en/schedule/thu-ssac SSAC's Presentation at ICANN Singapore] that addresses DDoS attacks and recommendations
  
 +
==Related Articles==
 +
*[[Botnet Attacks]]
 +
*[[DoS Attack]]
  
 +
==References==
 +
<references/>
  
[[Category:Glossaries]]
+
[[Category: Bad Practice]]

Revision as of 12:33, 23 May 2017

Distributed Denial of Service Attacks, or DDoS Attacks, effectively flood websites or servers with traffic from many different sources in order to "make the site unavailable."[1] DDoS is a type of Denial of Service Attack (DoS Attack) that uses multiple sources in order to blocks users from accessing the site. It is important to remember that not all service errors are the result of attack behaviors and can occur if a website is overwhelmed by non-malicious traffic as well.[2]

Public Perception

The public perception of DDoS attacks is negative. It is inconvenient to users who cannot reach their destination, and it can create major problems for the website's registrant, whether it is the website of an individual or an organization. DDoS attacks can become criminal when the attacker asks for money to stop the current attack or to prevent further attacks.[3] DDoS attacks can also be used by "hacktivists" for political gain, to interrupt free speech, or in protest of perceived injustice.[1][3]

Outcome

The outcome of a DDoS attack is that the attacked website is unavailable or runs very slowly. The damage done by these attacks can lead to minor inconveniences, losses in consumer confidence, or large revenue losses.

Historical Use

  • DDoS attacks have been used to take down or interrupt the traffic of large sites, making them inaccessible.[4][5] These planned attacks can be committed for political, social, and/or illegal purposes.[3] Unlike regular DoS attacks, DDoS attacks use multiple computers to attack their victims which often makes the attack harder to stop.[4] Botnets, or networks of computers controlled by hackers, are often used in DDoS attacks.[6]
  • Four types of DDoS attacks include:[1]
  1. TCP Connection Attacks: attempting "to use up all the available connections to infrastructure devices"[1]
  2. Volumetric Attacks: attempting to use large amounts of bandwidth
  3. Fragmentation Attacks: sending so many TCP or UDP fragments that the target cannot assemble them, which slows the system
  4. Application Attacks: trying to flood one aspect or application on a given site
  • A DDoS attack can be bought or traded as a service. For example, an attack that lasts a week can be purchased for $150,[1] while an attack that lasts 1 hour can be bought for $30-70.[7]
  • In addition to causing service errors, DDoS attacks can also be used to commit "other cybercrimes, including data breaches or financial fraud."[8]

ICANN Policy

  • ICANN does not have a policy that specifically addresses DDoS attacks; however, ICANN's blog has addressed the issue of how to respond to and report a DDoS attack.[3] If a site is under attack, the 2013 post suggests that the registrant contacts the hosting provider and internet service provider (ISP).[3] If the attack was proceeded by a threat or a sum of money was demanded to stop the attack, the registrant should contact law enforcement.[3]
  • ICANN's Security and Stability Advisory Committee (SSAC) also released an advisory in 2006 on DDoS attacks in relation to the DNS.[9]
  • ICANN's SSAC released another advisory in 2014 on DDoS attacks and how they may exploit certain security issues in the DNS.[10] For example, an attacker may use a victim's spoofed IP address to make multiple queries to an open recursive DNS server; the server will then respond by flooding the victim's computer with the unsolicited responses.[11] DDoS attacks that utilize "DNS reflection and amplification" can have "attack data bit rates reportedly exceeding 300 gigabits per second."[11] The advisory suggests that "ICANN should...facilitate an Internet-wide community effort to reduce the number of open resolvers and networks that allow network spoofing."[10] Additionally, rate limiting and blocking abusive queries may help reduce DDoS attacks.[11] The SSAC also recommends that DNS software and systems be updated regularly to reduce DDoS vulnerability.[11]

Legislation

  • Computer Fraud and Abuse Act (CFAA): this act, last amended in 2008,[12] prohibits the unauthorized use of another person's computer, among other things.[13][14] In relation to DDoS attacks, if the hacker used a botnet to perpetrate the attack, he or she could be charged under CFAA in addition to facing civil suits.[15] DDoS attackers can also face jail time.[16]
    • Read more about the CFAA.
  • Other nations, such as the UK and Sweden, also have anti-DDoS legislature.[16]

DNS Award

Awardees take a proactive approach to preventing DDoS attacks.

Additional Resources

Related Articles

References

  1. 1.0 1.1 1.2 1.3 1.4 What is a DDoS Attack?, Digital Attack Map
  2. Security Tip (ST04-015): Understanding Denial-of-Service Attacks (February 6, 2013), United States Department of Homeland Security
  3. 3.0 3.1 3.2 3.3 3.4 3.5 How to Report a DDoS Attack by Dave Piscitello (April 25, 2013), Internet Corporation for Assigned Names and Numbers (ICANN).
  4. 4.0 4.1 How to Prevent DoS Attacks by Aaron Weiss (July 2, 2012), eSecurity Planet
  5. Do More to Prevent DNS DDoS Attacks by Dave Piscitello (April 3, 2013), Internet Corporation for Assigned Names and Numbers (ICANN)
  6. What is DDoS denial of service? What everyone needs to know about DDoS, Prolexic
  7. Russian Underground 101 (PDF) by Max Goncharov, TrendMicro.com
  8. Best practices to mitigate DDoS attacks by Linda Musthaler (January 10, 2013), Network World
  9. SSAC Advisory SAC008: DNS Distributed Denial of Service (DDoS) Attacks (PDF), ICANN Security and Stability Advisory Committee (SSAC)
  10. 10.0 10.1 SSAC Advisory on DDoS Attacks Leveraging DNS Infrastructure (PDF), ICANN Security and Stability Advisory Committee (SSAC)
  11. 11.0 11.1 11.2 11.3 SSAC's Update Presentation at ICANN 49 (PDF and audio)
  12. Computer Fraud and Abuse Act at Wikipedia
  13. Computer Fraud and Abuse Act (CFAA) at Internet Law Treatise
  14. Computer Fraud and Abuse Act (CFAA) at Practical Law, Thomson Reuters
  15. Distributed Denial-of-Service (DDoS) Attack at Practical Law, Thomson Reuters
  16. 16.0 16.1 Are DDoS (distributed denial-of-service) attacks against the law? by Graham Cluley (December 9, 2010), Naked Security, Sophos