ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

DNS recursion leads to nastier DoS attacks

Dawn Kawamoto CNET News.com

Published: 17 Mar 2006 10:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new kind of denial-of-service (DoS) attack has emerged that delivers a heftier blow to organisations' systems than previously seen DoS threats, according to VeriSign's security chief.

The new DoS attacks first emerged in late December and kicked into high gear in January, before dying down four weeks ago, said Ken Silva, VeriSign's chief security officer. In less than two months, 1,500 separate IP addresses were attacked using this method, he noted.

"These attacks have been significantly larger than anything we've seen," he said.

Under a more common distributed DoS (DDos) attack, a botnet — a network of compromised PCs being remotely controlled — directly inundates a victim's Web server, name server or mail server with a multitude of queries. The goal of a DoS attack is to crash the victim's system or take their Web site offline, as either tries to respond to the requests.

But in this latest spate of DDoS attacks, bots are sending queries to DNS servers with the return address pointed at the targeted victim. As a result, the DNS server, rather than the bot, makes the direct attack on the victim. The net result is a stronger attack and an increased difficulty in stopping it, Silva said.

While it is possible to stop a bot-delivered DDoS attack by blocking the bots' IP addresses, blocking queries from DNS servers would prove more difficult, Silva said. He noted that companies could reconfigure their DNS servers to prevent the so-called recursive name service feature, as a possible solution. But he added that companies may be loath to prevent potential customers, partners, researchers and others from sending queries to their DNS.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
99 out of 181 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Backbone Network Engineer

Help design data centre installations and build-outs - Capacity planning - Troubleshoot a wide range of issues - Escalation point for network related ...

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Unix / Linux Redhat Systems Administrator- Market Leaders- London

Unix / Linux Redhat Systems Administrator Scripting, Oracle, MySql, DNS, DHCP, Apache, My client is a FSTE 100 blue chip organisation looking for ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment