Advertisement
Promo

Industry watch Toolkit

Newest anti-hacking defence systems? Speedier downloads

John Borland CNet

Published: 30 Jan 2001 09:31 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Thanks to the recent attacks on Microsoft's Web sites, technology for speeding downloads has transformed overnight into the latest anti-hacking defence systems.

The young content delivery services offered by Akamai Technologies, Speedera Networks and a lengthening list of others have until now been known for attracting companies from Yahoo! on down for their ability to shave critical seconds off the time surfers wait for Web pages to load.

But it turns out these companies' services are also an unexpected defence against attacks of the nature that made many of Microsoft's sites virtually inaccessible last week. Microsoft said Monday it had given Akamai responsibility for handling its domain name system, which is the technology that translates Web addresses like "MSN.com" into the numerical system understood by most computers.

"It's not a preventative measure, but it does mitigate the effects of a denial-of-service attack," said Scott Blake, security program manager for Bindview's Razor consulting team. "There are so many points of entry... that it makes it a lot more expensive for someone to shut down the system."

Content delivery technologies like Akamai are based on moving as much content as possible -- starting with static graphics and moving to streaming media and even some personalisation features -- as close as possible to individual Web surfers. The companies place thousands of servers inside hosting centres and individual ISP networks, so that as many people as possible have to go just one or two steps through the Net to reach most of a Web site, instead of transmitting data across the country.

Compare that with the mechanism behind so-called DDoS (distributed denial-of-service) attacks, which were the type that pushed Yahoo!, eBay, CNN and others offline a year ago, and apparently contributed to Microsoft's woes last week.

In DDoS attacks, the instigator quietly takes control of multiple machines around the Internet, priming them to act together at a single command. Launching the attack sends a stream of data or even ordinary Web site requests at a single server, router or network, in hopes of overloading the systems so they fail or are inaccessible to others. This brute-force attack does not generally yield the attacker any internal data such as personal or credit card information, but can be temporarily devastating for the company attacked.

The content delivery network serves as a natural check on this kind of attack. Because so much of the content is distributed across thousands of places in the network, it's harder to reach.

Networks like Akamai's haven't been seen primarily as an anti-hacking tool. But analysts note that handling spikes of traffic at peak periods of demand -- one of the key problems they are designed to solve -- is almost precisely the same as a DDoS attack.

"In general, when you move things to the edge of the network, denial of service becomes more difficult," said Peter Christy, an analyst with Jupiter Research.

This has long been an undermarketed feature in the content delivery systems, but Microsoft's adoption of Akamai's network as a defence is likely to help the whole industry by shifting potential customers' perceptions of what they're getting, the analyst added.

Is your PC safe? Find out at the Hackers News Special.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
53 out of 99 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Discussions

siarad siarad

Linux useless for home PC

Sunday 29 November 2009, 11:12 AM

1 comment
Fat Pop Do Wop Fat Pop Do Wop

How far will it all go?

Sunday 29 November 2009, 12:04 AM

3 comments
siarad siarad

Maybe, similarly,

Saturday 28 November 2009, 8:42 AM

3 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters