Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home IT Management
    • IT Management

    ICANN Targets DDoS Attacks

    Written by

    Dennis Fisher
    Published October 28, 2002
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      In the wake of last weeks unprecedented DDoS attack against all 13 of the Internets root-name servers, the government and ICANN, one of the Internets main governing bodies, are considering changes to help protect the DNS system against future attacks.

      The most immediate and significant changes will likely come from the Internet Corporation for Assigned Names and Numbers, which is holding a meeting this week in Shanghai, China. The body, which is ultimately responsible for maintaining the root servers that contain the master list of Internet domains, will hear recommendations from its Security and Stability Advisory Committee on securing the edge of the Domain Name System network. Specifically, the committee will recommend that ISPs take steps to prevent packets with forged IP addresses from being used in distributed-denial-of-service attacks, according to sources.

      Typically, virtually all packets in such attacks carry forged IP addresses, making it difficult for engineers to trace or filter them. The technology to prevent forwarding of such packets has been in most routers for several years, but ISPs have been reluctant to use it.

      “They dont turn it on because it makes extra work for them and doesnt earn them any more money,” said Paul Vixie, chairman of the Internet Software Consortium, a root server operator in Redwood City, Calif., and a member of the ICANN Security and Stability Advisory Committee. “Theres more we need to do because [the attacks] will get worse.”

      Also in the name of added security, the operators of the root-name servers–each of which is actually several machines in multiple locations–will add more servers to make the system more resistant to attacks and spread out the effects of large-scale DDoS events, according to Vixie.

      Security experts say such changes have been needed for some time and that last weeks attack simply makes them more imperative.

      Meanwhile, U.S. government security officials are discussing the possibility of creating new regulations that would require federal agencies to buy Internet service only from ISPs that have DDoS protection on their networks, according to people familiar with the situation. Such a decision could place economic pressure on the other ISPs to follow suit, thereby improving Internet security.

      The Oct. 21 attack reportedly took down as many as nine of the 13 root servers that contain the master domain list for the DNS for the Internet. However, security watchdog groups and Internet performance authorities said there was little noticeable change in Internet performance for most users.

      The attack was an Internet Control Message Protocol flood–also known as a ping flood–which sends a huge number of status requests to servers, sources familiar with the incident said. A spokesman for VeriSign Inc., in Mountain View, Calif., which operates two of the root servers, including the “A,” or master, server, said the servers were receiving as many as 150,000 requests per second during the height of the attack.

      Although last weeks attempt didnt bring the Internet down, thats no cause for celebration, experts say.

      “By no means has this problem gone away. This one wasnt very sophisticated, so its clear that some of the root operators werent as prepared as they couldve been,” said Paul Mockapetris, chief scientist at security vendor Nominum Inc., also in Redwood City, and the principal designer of the current DNS system. “The [top-level domains] are even more vulnerable. Its the next generation of attacks that we need to worry about.”

      Other observers suggested that ISPs–which typically share capacity during emergencies such as DDoS attacks–should have access to a pool of ready bandwidth.

      “The problem with this was, no one had excess capacity to share,” said Mark Rasch, senior vice president and chief security counsel at Solutionary Inc., based in Omaha, Neb.

      For their part, ISPs say that their range of options for DDoS protection is limited. “There doesnt appear to be any public product suite that we can provide to customers to prevent this,” said Jennifer Baker, a WorldCom Inc. spokeswoman based in Washington.

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×