In case you're thinking the Internet has been a little slow this last week, rest easy: it has been. The slowness is due to a war between the anti-spam group Spamhaus and a Dutch web hosting company called Cyberbunker. As The New York Times' John Markoff and Nicole Perlroth explain:
The dispute started when the spam-fighting group, called Spamhaus, added the Dutch company Cyberbunker to its blacklist, which is used by e-mail providers to weed out spam. Cyberbunker, named for its headquarters, a five-story former NATO bunker, offers hosting services to any Web site except child porn and anything related to terrorism, according to its Web site.
A spokesman for Spamhaus, which is based in Europe, said the attacks began on March 19, but had not stopped the group from distributing its blacklist.
Patrick Gilmore, chief architect at Akamai Technologies, a digital content provider, said Spamhauss role was to generate a list of Internet spammers.
Of Cyberbunker, he added: These guys are just mad. To be frank, they got caught. They think they should be allowed to spam.
CloudFlare, which is the company that provides DDOS mitigation, explains the attack against their client, Spamhaus, and how the tremendous amount of data being sent for the attack slowed down the Internet for everyone else on it.
Anycast means that if the attacker attacked the last step in the traceroute then their attack would be spread across CloudFlare's worldwide network, so instead they attacked the second to last step which concentrated the attack on one single point. This wouldn't cause a network-wide outage, but it could potentially cause regional problems.
We carefully select our bandwidth providers to ensure they have the ability to deal with attacks like this. Our direct peers quickly filtered attack traffic at their edge. This pushed the attack upstream to their direct peers, largely Tier 1 networks. Tier 1 networks don't buy bandwidth from anyone, so the majority of the weight of the attack ended up being carried by them. While we don't have direct visibility into the traffic loads they saw, we have been told by one major Tier 1 provider that they saw more than 300Gbps of attack traffic related to this attack. That would make this attack one of the largest ever reported.
The challenge with attacks at this scale is they risk overwhelming the systems that link together the Internet itself. The largest routers that you can buy have, at most, 100Gbps ports. It is possible to bond more than one of these ports together to create capacity that is greater than 100Gbps however, at some point, there are limits to how much these routers can handle. If that limit is exceeded then the network becomes congested and slows down.
Over the last few days, as these attacks have increased, we've seen congestion across several major Tier 1s, primarily in Europe where most of the attacks were concentrated, that would have affected hundreds of millions of people even as they surfed sites unrelated to Spamhaus or CloudFlare. If the Internet felt a bit more sluggish for you over the last few days in Europe, this may be part of the reason why.
|Most Social Media Users Expect Cries for Help To Be Answered Quickly|
|Timesify: Makes Every Webpage Look Like the New York Times|
|Should Google Flag Bogus Websites?|
|"The on-demand world isn't about sharing at all. It's about being served. This is an economy of shut-ins."|
|What Happens if You Like Everything on Facebook|
|“Both spacecraft are still operational when they reached interstellar space.”|
|"Free apps make money by selling your personal data."|
|CaptchaTweet: Write Tweets in Captcha Form|
|How to Avoid Jury Duty|
|“Initial riders may be more comfortable getting into a car with a human in the driver seat.”|
|The (Very Scary) People of Public Transit|
|The Festive Funk Machine: Click to Make Your Own Festive Music|
|Naked Preacher Lady [NSFW]|
|Fake Name Generator|
|“We’ve received requests to add some artificial noise to the buses so that people can hear them.”|