Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Spamhaus DDoS Attack Investigation Results in Arrest of Dutch Man

    Written by

    Brian Prince
    Published April 30, 2013
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A 35-year-old man was arrested last week in Spain in connection with the massive distributed denial-of-service (DDoS) attack on Spamhaus in March.

      The suspect was identified by authorities only as a Dutchman with the initials “SK,” though he has been identified in reports as Sven Olaf Kamphuis, who has been tied to Web hosting company Cyberbunker that critics say does business with spammers and other cyber-criminals.

      The arrest could be a significant break in the Spamhaus incident that some have called the biggest DDoS attack on record. The attack was initially directed at the infrastructure of Spamhaus, a non-profit organization dedicated to fighting spam.

      Over the course of two weeks in March, the attacks escalated from targeting just Spamhaus’ Websites, mail servers and name servers, to targeting Spamhaus’ supporting networks and services—including various Internet exchanges. Leveraging open DNS resolvers, the attack was able to get control of massive amounts of traffic. At its height, the attack is said by some to have peaked at an estimated 300G bps.

      “The attacks against Spamhaus used what techies call ‘DNS amplification’,” blogged Paul Ducklin, Sophos’ head of technology for Asia-Pacific. “This relied on your home firewall, or your router at work, being wrongly configured. The attackers could then exchange tiny packets of data with you, asking you to get DNS information from Spamhaus; you’d then convert that into a much larger exchange of data packets with Spamhaus itself,” Ducklin wrote.

      “By dispersing a few hundred bytes each to a few hundred misconfigured routers, the attackers could produce tens of megabytes of network traffic focused back onto [Spamhaus’] servers,” he added.

      According to Arbor Networks, which specializes in DDoS protection, the average size of DDoS attacks continues to grow every year. For example, the average attack size in 2012 was 1.48G bps, up more than 20 percent from 2011. In the first quarter of 2013, the average attack size jumped to 1.77G bps.

      “Although volumetric DDoS attacks have grown in size over the past few years, the Spamhaus attack was definitely an outlier; however, attacks above 10 and even 20Gb/sec now occur multiple times per day somewhere in the world,” blogged Darren Anstee, lead solution architect at Arbor Networks, April 22. “Every day hundreds, or even thousands, of attacks take place utilizing different attack vectors, having different levels of complexity and different motivations and resources behind them. For enterprise network operators, it is important to have a broad view of what is going on out there,” Anstee wrote.

      In the case of the Spamhaus attack, the suspect’s house was searched at the request of the national prosecutor in Barcelona and computers, mobile phones and other equipment were seized. The investigation was conducted in the Netherlands by the High Tech Crime Team.

      According to authorities, there is no evidence the attack on Spamhaus is related to attacks on iDeal or DigiD that happened after the incident targeting Spamhaus. Nor is there any apparent connection to a series of attacks known as Operation Ababil, which has struck financial institutions as varied as American Express, Citibank and Bank of America in waves during the past several months.

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.