DDoS attacks spread to vulnerable IPv6 Internet
(Credit: Arbor Networks)
The idyllic byways of the next-generation IPv6 Internet now suffer an affliction previously limited to the mainstream IPv4 Internet: distributed denial-of-service attacks.
And worse, the still-immature IPv6 network is being caught with its pants down when it comes to repelling the DDoS attacks. That's the conclusion of Arbor Networks' latest annual study on the Internet's operational security, released today.
(Credit: Arbor Networks)
"This is a significant milestone in the arms race between attackers and defenders," Arbor Networks said. "We believe that the scope and prevalence of IPv6 DDoS attacks will gradually increase over time as IPv6 is more widely deployed."
For the moment, the volume is still relatively small--only 4 percent of survey respondents reported seeing IPv6 DDoS attacks--but that's a worrisome harbinger.
DDoS attacks use a swarm of computers to swamp a target machine on the Internet with traffic so it's unusable. Such attacks sometimes are launched from botnets of compromised computers for criminal reasons--but now the top cause is ideology such as that evident in Anonymous' coordinated protest attacks.
DDoS attacks send traffic to a particular Internet address, and today the vast majority of those addresses are handled by Internet Protocol version 4, or IPv4. IPv6, which vastly increases the number of possible addresses to deal with the fact that IPv4 is running out of them, is gradually becoming a reality as those with servers and network gear invest in the new network.
(Credit: Arbor Networks)
IPv6 isn't the main route for attacks, since it's still a relative backwater, but two problems make IPv6 particularly vulnerable. First, with the relatively immature network infrastructure, many network operators don't have the ability to scrutinize network traffic well enough to distinguish DDoS attacks from benign traffic. Second, gateways that link IPv4 and IPv6 must store lots of "state" information about the network traffic they handle, and that essentially makes them more brittle.
Arbor forecasts greater protections, though. "Twenty percent of respondents indicated that they have no plans to mitigate IPv6 DDoS attacks. We suspect that priorities within these organizations may evolve rapidly as IPv6 network traffic becomes more prevalent," Arbor said.
Investments in countermeasures are expensive--but so are DDoS attacks.
Survey respondents reported varying costs of dealing with a DDos attack: about $1,300 or $8,000 in two cases, $250,000 or $300,000 in two others, and $1 million to $1.5 million in two others. And of course there are other costs, for example when a business or government can't get work done or sell products.
(Credit: Arbor Networks)
Powerful attacks the "new normal"
The study, a global survey of network operators such as Internet service providers, also finds that DDoS attacks have become more powerful, more sophisticated, and more routine. And the leading cause: ideological attacks such as launched by Anonymous after MegaUpload arrests.
"Ideology was the most common motivating factor for DDoS attacks in 2011, followed by a desire to vandalize," Arbor Networks said. The finding is "one of the single most important data points in this year's report, with major implications in terms of threat assessment, situational awareness, and continuity of operations for network operators, governmental bodies, law enforcement agencies, and end customers alike."
(Credit: Arbor Networks)
Although the top bandwidth of an attack decreased from 2010's 100 gigabits per second to 2011's 60 gigabits per second, it's increasingly common to see attacks that send tremendous traffic, Arbor said.
"During the survey period, respondents reported a significant increase in the prevalence of flood-based DDoS attacks in the 10Gbps range. This represents the 'mainstreaming' of large flood-based DDoS attacks, and indicates that network operators must be prepared to withstand and mitigate large flood attacks on a routine basis," the report said.
Growing DDoS sophistication
In earlier years, distributed denial-of-service attacks traveled by lower-level network protocols such as TCP (Transmission Control Protocol), which is used to ensure that data is successfully delivered across a network.
Now, though, attacks are moving to higher-level services such as HTTP (Hypertext Transfer Protocol), which is used to send Web pages to browsers; DNS (Domain Name Service) for translating text-based Internet addresses into their numeric equivalents; SMTP (Simple Mail Transfer Protocol) for sending e-mail; HTTPS for encrypted Web page communications; and voice over Internet Protocol (VOIP).
That's driven in part by new attack software. "HTTP GET and HTTP POST [two HTTP commands] were the most common application-layer DDoS attack vectors, more sophisticated mechanisms such as Slowloris, LOIC, Apache Killer, SIP call-control floods, SlowPost and HOIC are increasingly prevalent," Arbor found.
(Credit: Arbor Networks)
See the rest here:
DDoS attacks spread to vulnerable IPv6 Internet
- World IPv6 Launch Unites Industry Leaders to Redefine the Global Internet - June 6th, 2012 [June 6th, 2012]
- The Internet now has 340 trillion trillion trillion addresses - June 6th, 2012 [June 6th, 2012]
- Internet has 340 trillion trillion trillion addresses - June 6th, 2012 [June 6th, 2012]
- Internet now has 340 undecillion addresses - June 6th, 2012 [June 6th, 2012]
- Cisco creates a smarter Internet - June 5th, 2012 [June 5th, 2012]
- How the Internet Became Boring - June 5th, 2012 [June 5th, 2012]
- Cisco's new, smarter network for the Internet of things - June 5th, 2012 [June 5th, 2012]
- Internet co-creator Vint Cerf welcomes IPv6 elbow room (Q&A) - June 5th, 2012 [June 5th, 2012]
- Microsoft Just Made the Internet a Little More Private for Everyone - June 5th, 2012 [June 5th, 2012]
- Jefferies Hires Two Senior Analysts to Cover Internet and Interactive Entertainment - June 4th, 2012 [June 4th, 2012]
- Xerocole CTO Exposes Biggest Challenges Facing Internet Service Providers on World IPv6 Launch Day - June 4th, 2012 [June 4th, 2012]
- Kinect-enhanced Internet Explorer coming to Xbox - June 4th, 2012 [June 4th, 2012]
- Internet Solution Source Provides Options to Boost Morale of Stay-at-Home Moms - June 4th, 2012 [June 4th, 2012]
- Internet powers flip the IPv6 switch (FAQ) - June 4th, 2012 [June 4th, 2012]
- Internet Industry Gears up for World IPv6 Launch - June 4th, 2012 [June 4th, 2012]
- Could You Spare Some Internet Access? - June 4th, 2012 [June 4th, 2012]
- The Nation's Top Internet Marketers Shine in Chicago at the Internet Prophets Live Event - June 4th, 2012 [June 4th, 2012]
- Internet's net result on election results - June 3rd, 2012 [June 3rd, 2012]
- Report From Internet Prom 2012 - June 3rd, 2012 [June 3rd, 2012]
- SciTechTalk: Proposed United Nations control of Internet raises alarms - June 3rd, 2012 [June 3rd, 2012]
- Internet address system upgrade likely to be smooth - June 3rd, 2012 [June 3rd, 2012]
- Internet Explorer 10: embedded Flash, Do Not Track, and stable standards - June 2nd, 2012 [June 2nd, 2012]
- FBI: New Internet addresses could hinder police investigations - June 2nd, 2012 [June 2nd, 2012]
- Internet Society’s Sally Wentworth Testifies Before U.S. House of Representatives on International Internet Regulations - June 1st, 2012 [June 1st, 2012]
- The Internet: A Series Of 'Tubes' (And Then Some) - May 31st, 2012 [May 31st, 2012]
- U.N.'s push to regulate the Internet - May 31st, 2012 [May 31st, 2012]
- Internet connections to reach 19 billion by 2016 - May 31st, 2012 [May 31st, 2012]
- Where's the outcry on the U.N. push to regulate the Internet? - May 31st, 2012 [May 31st, 2012]
- U.S. tech companies warn of threat to Internet from foreign governments - May 31st, 2012 [May 31st, 2012]
- The Future Growth of the Internet, in One Chart (and One Graph) - May 31st, 2012 [May 31st, 2012]
- Mike Tyson training Justin Bieber - Video - May 30th, 2012 [May 30th, 2012]
- A 'bat signal' to defend open Internet - May 30th, 2012 [May 30th, 2012]
- Virtual Internet Nominated for Multiple Awards - May 30th, 2012 [May 30th, 2012]
- Internet Marketing Inc. Names Ben Norton New President & COO - May 30th, 2012 [May 30th, 2012]
- A 'bat signal' for the open Internet - May 30th, 2012 [May 30th, 2012]
- Internet dating safety bill in Illinois would disclose background check policies - May 29th, 2012 [May 29th, 2012]
- Internet Defense League Crafts 'Bat Signal' for the Web - May 29th, 2012 [May 29th, 2012]
- Keep the Internet an open forum - May 28th, 2012 [May 28th, 2012]
- Internet Retailing in Emerging Markets: Long-Term Growth Opportunities in BRIC Countries - May 28th, 2012 [May 28th, 2012]
- Internet Shows Signs of Challenging TV for Attention - May 28th, 2012 [May 28th, 2012]
- Internet Freedom Advocates Take a Page From Caped Crusader - May 27th, 2012 [May 27th, 2012]
- Internet Defense League plans ‘Bat-Signal’ for the Web to combat dangerous bills - May 26th, 2012 [May 26th, 2012]
- Internet Defense League introduces 'cat signal' for websites - May 26th, 2012 [May 26th, 2012]
- No Parachute Skydive ~ Things I Found on The Internet Friday ~ Episode #2 [HD] - Video - May 25th, 2012 [May 25th, 2012]
- Employment up over 40% at First Internet Bank - May 25th, 2012 [May 25th, 2012]
- Internet phone service bill advances in California Senate - May 25th, 2012 [May 25th, 2012]
- How Alcatel-Lucent made the Internet 5 times faster - May 23rd, 2012 [May 23rd, 2012]
- Chrome overtakes Internet Explorer as No. 1 browser -- maybe - May 23rd, 2012 [May 23rd, 2012]
- Atlantis Internet Group Adds Two More Tribes to Its Tribal Gaming Network - May 23rd, 2012 [May 23rd, 2012]
- Internet domain name project relaunches after software bug - May 23rd, 2012 [May 23rd, 2012]
- Meet the Man Who Invented the Instructions for the Internet - May 20th, 2012 [May 20th, 2012]
- Internet Governance Must Ensure Access for Everyone – UN Exp - May 20th, 2012 [May 20th, 2012]
- Chinese Internet Stocks Posting Mixed Results - May 20th, 2012 [May 20th, 2012]
- Ellen Through Time - Video - May 17th, 2012 [May 17th, 2012]
- Aaron Sorkin hates the Internet. Why does he keep writing about tech geniuses? - May 17th, 2012 [May 17th, 2012]
- Research and Markets: Internet and Online Privacy: A Legal and Business Guide - May 17th, 2012 [May 17th, 2012]
- Internet usage patterns may signify depression - May 17th, 2012 [May 17th, 2012]
- THE AMAZING SPIDER-MAN (3D) - 4 MINUTE SUPER PREVIEW - Video - May 15th, 2012 [May 15th, 2012]
- Internet Week New York: Facebook opens doors - May 15th, 2012 [May 15th, 2012]
- Internet radio on the rise thanks to social media and tablets, says study - May 15th, 2012 [May 15th, 2012]
- Rising Internet Use Fuels Teen Smartphone Addiction - May 15th, 2012 [May 15th, 2012]
- Internet Radio Not Quite Warming to Social Media Yet - May 15th, 2012 [May 15th, 2012]
- Internet Broadcasting Adds New HTML5 Ad Products To Give Clients More Options For Rich Mobile Advertising - May 15th, 2012 [May 15th, 2012]
- NextLevel Internet Expands Executive Management Team - May 15th, 2012 [May 15th, 2012]
- Internet Society Launches Regional Office in Singapore - May 15th, 2012 [May 15th, 2012]
- Internet news saved forever? - Video - May 12th, 2012 [May 12th, 2012]
- Internet safe spot planned at ".secure" domain - May 12th, 2012 [May 12th, 2012]
- Startup proposes a safer Internet locale via a '.secure' domain - May 12th, 2012 [May 12th, 2012]
- California regulator delays taking stand on Internet phone measure - May 12th, 2012 [May 12th, 2012]
- Internet Explorer Rumored to be Heading to Xbox 360 - May 12th, 2012 [May 12th, 2012]
- Internet gambling in N.J. rolls one step closer to reality - May 12th, 2012 [May 12th, 2012]
- Seeking Chen Guangcheng's freedom in China via 'Internet meme' - May 9th, 2012 [May 9th, 2012]
- ThinkGeek Ascends to #175 in Internet Retailer's 2012 Top 500 List - May 9th, 2012 [May 9th, 2012]
- Clearband Hi-Speed Internet Services Launches in South Florida - May 9th, 2012 [May 9th, 2012]
- Internet Gold Reports First Quarter 2012 Financial Results - May 9th, 2012 [May 9th, 2012]
- Internet revolution bypasses rural India: Survey - May 6th, 2012 [May 6th, 2012]
- UK wants Internet providers to block porn by default - May 6th, 2012 [May 6th, 2012]
- Internet group: Quality over speed in new domains - May 6th, 2012 [May 6th, 2012]
- Internet Adventure Hour: Interview with Hannah Hart - Video - May 2nd, 2012 [May 2nd, 2012]
- Blogger: 'I'm leaving the Internet' - May 2nd, 2012 [May 2nd, 2012]