In case you're thinking the Internet has been a little slow this last week, rest easy: it has been. The slowness is due to a war between the anti-spam group Spamhaus and a Dutch web hosting company called Cyberbunker. As The New York Times' John Markoff and Nicole Perlroth explain:
The dispute started when the spam-fighting group, called Spamhaus, added the Dutch company Cyberbunker to its blacklist, which is used by e-mail providers to weed out spam. Cyberbunker, named for its headquarters, a five-story former NATO bunker, offers hosting services to any Web site except child porn and anything related to terrorism, according to its Web site.
A spokesman for Spamhaus, which is based in Europe, said the attacks began on March 19, but had not stopped the group from distributing its blacklist.
Patrick Gilmore, chief architect at Akamai Technologies, a digital content provider, said Spamhauss role was to generate a list of Internet spammers.
Of Cyberbunker, he added: These guys are just mad. To be frank, they got caught. They think they should be allowed to spam.
CloudFlare, which is the company that provides DDOS mitigation, explains the attack against their client, Spamhaus, and how the tremendous amount of data being sent for the attack slowed down the Internet for everyone else on it.
Anycast means that if the attacker attacked the last step in the traceroute then their attack would be spread across CloudFlare's worldwide network, so instead they attacked the second to last step which concentrated the attack on one single point. This wouldn't cause a network-wide outage, but it could potentially cause regional problems.
We carefully select our bandwidth providers to ensure they have the ability to deal with attacks like this. Our direct peers quickly filtered attack traffic at their edge. This pushed the attack upstream to their direct peers, largely Tier 1 networks. Tier 1 networks don't buy bandwidth from anyone, so the majority of the weight of the attack ended up being carried by them. While we don't have direct visibility into the traffic loads they saw, we have been told by one major Tier 1 provider that they saw more than 300Gbps of attack traffic related to this attack. That would make this attack one of the largest ever reported.
The challenge with attacks at this scale is they risk overwhelming the systems that link together the Internet itself. The largest routers that you can buy have, at most, 100Gbps ports. It is possible to bond more than one of these ports together to create capacity that is greater than 100Gbps however, at some point, there are limits to how much these routers can handle. If that limit is exceeded then the network becomes congested and slows down.
Over the last few days, as these attacks have increased, we've seen congestion across several major Tier 1s, primarily in Europe where most of the attacks were concentrated, that would have affected hundreds of millions of people even as they surfed sites unrelated to Spamhaus or CloudFlare. If the Internet felt a bit more sluggish for you over the last few days in Europe, this may be part of the reason why.
|Second Life slapped with counterfeit sex toy suit|
|Twitter hacked by 'Iranian Cyber Army'|
|The Most Horrific Things Encountered While Online Dating|
|Record and Share MP3s Directly From Your Browser with RecordMP3|
|Termite-Inspired Autonomous Robotic Construction Crew|
|“The release of methane from hydrate may be apocalyptic.”|
|Unboxing a Factory Sealed IBM Compatible PC from 1988|
|The Unknown Reader|
|Reviewing Counterfeit Toys Made in China|
|James Charles' Pop Culture Dollars|
|"This very internationalism that contributed to the apocalyptic disaster that ended the Bronze Age."|
|“There was not only automation but where the suggestion that humans had any control [...] was absent too.”|
|"Most of what kids currently learn at school will probably be irrelevant by the time they are 40."|
|"Fossil fuel executives want to get a piece of the clean-energy business."|
|“You can make spaceships much bigger than anything we’ve seen so far in history.”|