140
Hal Roberts, Ethan Zuckerman, and John Palfrey
the identities of its users and also posted infl ammatory content to the forum to trigger
governmental prosecution. Yet another administrator reported that intruders had
repeatedly accessed internal databases to learn about stories before they were published. And another reported that attackers broke into his site to insert malicious code
with the intent of triggering antivirus warnings for the site and thereby scaring users
from accessing it. He also reported intrusions to his site that inserted code that slowed
the Internet connections of his users by causing them to download large packages of
Trojan horse software. In all cases, the DDoS attacks may have been the most visible
manifestation that a site was under attack. But the attacks that accompanied the DDoS
attacks were often of far more concern and import to the affected administrators.
DDoS attacks vary greatly in their nature and magnitude. In our interviews, we
heard about a range of attacks, extending from multi-Gbps fl oods of traffi c that overwhelmed the network connectivity of the affected sites to attacks that used as few as
a few dozen requests per minute to cripple sites by exploiting holes in Web servers
and other applications. Five of the interview participants reported attacks in the range
of 500 Mbps to 4 Gbps. One participant, who was the administrator of a large service
provider working for an independent media site, reported an attack of greater than
10 Gbps. Some of these attacks may have been bigger, since at greater than 1 Gbps,
many local ISPs become saturated and drop any additional traffi c. One interview
subject, whose site experienced several DDoS attacks in the previous four years,
reported an escalation of the size of attacks over time. His site had been successfully
disrupted in 2007 with a 1 Gbps DDoS attack, and he moved to more robust, DDoSresistant hosting provider. His contract with the provider specifi ed that he would be
protected from attacks up to 2 Gbps. When an attack in 2010 involved 4 Gbps of
traffi c, his host took his site offl ine, offering him the option of either increasing his
monthly payments or remaining offl ine until the attack ended.
Three interview participants reported application attacks at low — even very low —
bandwidths that caused signifi cant downtime. One was taken down by fewer than
40,000 requests per day, another by less than ten machines hitting his search page.
Two participants reported long-term success using mitigation strategies — caching and
Web application optimization — which would be effective against only relatively low
bandwidth attacks. We believe these attacks exploited known holes in application
software, such as the Slowloris attack against Apache Web servers.
13
It is likely that most or all network attacks that we encountered in our research
involved the use of botnets to generate incoming traffi c. Other indicators suggest that
some of the attacks involved the use of rented botnets. Two interview subjects reported
that attacks began and ended at the top of an hour, suggesting that a botnet had been
rented for a specifi c duration. The DDoS attack against the Berkman Center ’ s Citizen
Media Law Project offered further evidence of rented botnet attacks. The DDoS attack
was an application attack using HTTP GET requests originating from a shifting set of
Précédent

- 157/431

Suivant