Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Networking

    Claims China Hijacked ’15 Percent’ of Web Traffic Are ‘Overhyped,’ Experts Say

    Written by

    Fahmida Y. Rashid
    Published November 19, 2010
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The furor over a Chinese Internet service provider hijacking Internet traffic in April is in danger of being overhyped and obscuring real security issues, according to security experts.

      The hijacking incident occurred for 18 minutes on April 8, when China Telecom, China’s largest Internet service provider, published a set of instructions under the Border Gateway Protocol (BGP) that incorrectly directed Web traffic from about 37,000 networks to route through its servers. According to BGPmon, a group that collects routing data from around the world, China Telecom normally routes about 40 networks.

      The U.S.-China Economic and Security Review Commission report addressed the incident, noting that the “erroneous” network traffic instructions routed Internet traffic through Chinese servers. “Other servers around the world quickly adopted these paths, routing all traffic to about 15 percent of the Internet’s destinations through servers located in China,” the report said.

      That “15 percent” appeared to be problematic for many security experts. Craig Labovitz, chief scientist at Arbor Networks, told eWEEK that despite sundry reports and analysis, the hijack did not route 15 percent of Internet traffic.

      “This information didn’t propagate. It didn’t impact the world,” Labovitz said.

      Labovitz compared China Telecom’s publishing BGP instructions to publishing a “corrupted” telephone directory. While the potential was there for traffic to get misrouted, the directory, or the actual instructions, did not actually spread very far, he said.

      Even though China Telecom claimed to route networks not assigned to them, “only about 10 percent” propagated outside of China, according to the BGPmon blog. The majority were Chinese networks, although Websites belonging to CNN, Dell and Amazon were on the list.

      The Congressional report also listed specific U.S. government-owned sites, including those belonging to all four military branches, the office of the Secretary of Defense and NASA, as well as Yahoo and Microsoft.

      “Most of the Internet ignored the hijack for various technical reasons,” wrote Labovitz on his blog.

      Labovitz cited an April post from Robert Kisteleki of R??«seaux IP Europ??«ens (RIPE, French for “European IP Networks”) claiming the incorrect instructions had not reached European networks. “No one in Europe actually got diverted,” and the ones mostly affected were the Chinese networks, said Labovitz.

      Arbor Networks also collects information from about 120 carriers around the world, collecting real-time data about their traffic in its ATLAS system. The ATLAS data can be viewed on a country level, and Labovitz said there was no “statistically significant increase” in traffic being routed to China on April 8. “Diverting 15 percent of the Internet even for just 15 minutes would be a major event,” said Labovitz, and would have shown up as a significant spike in ATLAS’ country data.

      If European traffic was unaffected and the data doesn’t show a traffic spike to China, what could have happened?

      Labovitz said that “15 percent” could refer to actual routes, or the instructions, China Telecom published, and not actual Internet traffic volume. So it was possible-and more likely-that China Telecom took it upon itself to claim 15 percent of all the routes that it wasn’t assigned to, and that was significantly different from actual Web traffic, said Labovitz.

      The language in the report doesn’t explicitly state whether it refers to traffic or routes.

      Labovitz expressed concern over the lack of security in DNS, saying the world was on “borrowed time” before a serious incident occurred. But he said that misrepresenting the incident was dangerous. It obscured “important security issues” surrounding the fact that Internet traffic was routed on a system relying “primarily on trust” and had no security standards.

      “But in an industry crowded with security marketing and hype, it is important we limit the hyperbole and keep the discussion focused around the legitimate long-term infrastructure security threats and technical realities,” Labovitz wrote.

      While the report did not outright accuse the Chinese wireless service provider of doing harm, the commission said “the capability could enable severe malicious activities.”

      So how much traffic really did get diverted? Labovitz hedged his reply, saying the significance depended on actual companies and sites affected, before saying his data shows the actual number was “orders and orders of magnitude smaller, at 0.015 percent.”

      China Telecom has called the accusations “groundless” and that it “has never done such an act.” Labovitz and several other industry watchers have speculated that it was an accident because of the incident’s short interval.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.