Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Internet backbone suffers suspected attack

Joris Evers CNET News.com

Published: 07 Feb 2007 14:31 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

There are signs that hackers attacked key parts of the backbone of the internet on Tuesday, but no damage seems to have been done, experts said.

The attack appears to have focused on the Domain Name System (DNS), which maps text-based domain names, such as "ZDNet.co.uk", to the actual numeric IP addresses of servers connected to the internet, and vice versa. Several key DNS servers saw traffic spike in the early morning on Tuesday, several experts said — a sign of an attack.

"It is an unusual large amount of traffic that is hitting DNS servers," said John Crain, chief technical officer at the Internet Corporation for Assigned Names and Numbers, which operates one of the main so-called root DNS servers. "We see large attacks on a regular basis, but this hit quite a few servers, so it was fairly large."

Yet the DNS servers were able to withstand the onslaught, Crain added. "It was irritating. It ruined my night's sleep. It was extraordinary in the fact that it happened to multiple systems at once, but this is not affecting internet users," he said.

DNS serves as the address book for the internet. There are 13 official root DNS servers, which sit at the top of the DNS hierarchy. These root servers get queried only if other DNS servers, like those at an internet service provider, don't have the right IP address for a specific website.

If part of the DNS system goes down, websites could become unreachable and email could become undeliverable. But DNS is built to be resilient, and attacks on the system are rare. In 2002, a similar denial-of-service attack also failed.

"The main thing is that there was very little impact on the general public, the servers were able to hold up against the attacks," said Zully Ramzan, a researcher at Symantec Security Response. "The internet in general was designed to even withstand a nuclear attack."

The barrage of data apparently being targeted at the DNS system started at around 2.30am Pacific Time on Tuesday. Multiple root servers saw a traffic spike, but the "G" server, run by the US Department of Defense, and "L", run by ICANN, seem to have borne the brunt of it, Ramzan said. ICANN's Crain confirmed that impression.

While ICANN and Symantec didn't see any effect on the internet at large, internet service provider Neustar did see slow downs on the net. "We would call it a brownout instead of a blackout. It was significant, but it did not take anything down," a representative for the company said.

The true cause of the traffic surge still needs to be determined, both Ramzan and Crain said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
19 out of 19 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters