DDoS attackers have found this new trick to knock over websites

Distributed denial of service (DDoS) attackers are using a new technique to knock websites offline by targeting vulnerable ‘middleboxes’, such as firewalls, to amplify junk traffic attacks. 

Amplification attacks are nothing new and have helped attackers knock over servers with short busts of traffic as high as 3.47 Tbps. Microsoft last year mitigated attacks on this scale that were the result of competition between online-gaming players

But there’s a new attack on the horizon. Akamai, a content distribution network firm, says it has seen a recent wave of attacks using “TCP Middlebox Reflection”, referring to transmission control protocol (TCP) – a founding protocol for secured communications on the internet between networked machines. The attacks reached 11 Gbps at 1.5 million packets per second (Mpps), according to Akamai.

SEE: Cybersecurity: Let’s get tactical (ZDNet special report)

The amplification technique was revealed in a research paper last August, which showed that attackers could abuse middleboxes such as firewalls via TCP to magnify denial of service attacks. The paper was from researchers at the University of Maryland and the University of Colorado Boulder.

Most DDoS attacks abuse the User Datagram Protocol (UDP) to amplify packet delivery, generally by sending packets to a server that replies with a larger packet size, which is then forwarded to the attacker’s intended target. 

The TCP attack takes advantage of network middleboxes that don’t comply with the TCP standard. The researchers found hundreds of thousands of IP addresses that could amplify attacks by over 100 times utilizing firewalls and content filtering devices. 

So, what was a theoretical attack just eight months ago is now a real and active threat. 

“Middlebox DDoS amplification is an entirely new type of TCP reflection/amplification attack that is a risk to the internet. This is the first time we’ve observed this technique in the wild,” it says in a blogpost

Firewalls and similar middlebox devices from the likes of Cisco, Fortinet, SonicWall and Palo Alto Networks, are key pieces of corporate network infrastructure. Some middleboxes however don’t properly validate TCP stream states when enforcing content filtering policies. 

“These boxes can be made to respond to out-of-state TCP packets. These responses often include content in their responses meant to “hijack” client browsers in an attempt to prevent users from getting to the blocked content. This broken TCP implementation can in turn be abused to reflect TCP traffic, including data streams, to DDoS victims by attackers,” Akamai notes. 

Attackers can abuse these boxes by spoofing the source IP address of the intended victim to direct response traffic from the middleboxes. 

In TCP, connections use the synchronize (SYN) control flag to exchange key messages for a  three-way handshake. The attackers abuse the TCP implementation in some middelboxes that cause them to unexpectedly respond to SYN packet messages. In some cases, Akamai observed that a single SYN packet with a 33-byte payload produced a 2,156-byte response, amplifying its size by 6,533%.   

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
HBO and HBO Max are reportedly laying off 70 production staffers thumbnail

HBO and HBO Max are reportedly laying off 70 production staffers

The major cost-cutting drive at Warner Bros. Discovery is continuing, as the company is reportedly laying off around 70 workers across HBO and HBO Max. Most of the cuts are on the side of the streaming service, according to Deadline. The layoffs account for around 14 percent of staffers across the two divisions. HBO Max's…
Read More
BYD and Other New Energy Vehicle Firms Join Price War thumbnail

BYD and Other New Energy Vehicle Firms Join Price War

With the price war among Chinese fuel vehicle brands accelerating, there are signs of a price reduction trend for new energy vehicles as well, according to a report by The Paper on April 12. On April 10, Shenlan, a joint venture created under Changan, battery manufacturer CATL, and Huawei, announced the start of its “Shenlan
Read More
Mastodon simplifies sign-ups to attract new users thumbnail

Mastodon simplifies sign-ups to attract new users

After Elon Musk took over Twitter, one of the alternatives to the social media website that users flocked to was Mastodon. It's a decentralized network where people can choose from multiple servers or "instances," with each one being independently operated. At the moment, there are 12,000-plus instances people can choose from, and the Mastodon team
Read More
Android 13 erbjuder Material You design för alla appar thumbnail

Android 13 erbjuder Material You design för alla appar

I och med Android 12 introducerade Google något som hette Material You, vilket var en design där appar anpassade designen till ditt tema. Men med Android 13 ser det ut som att Google tagit detta ett steg längre!  You Might Also Like Ta en titt på första färska betan av Android 13 Android 13 Tiramisu…
Read More
Turkey's new quarantine rules announced!  Here are all the ingredients! thumbnail

Turkey's new quarantine rules announced! Here are all the ingredients!

Sağlık Bakanlığı, COVID-19 karantina ve izolasyon uygulamalarına ilişkin güncellenmiş bir kılavuz yayınladı. Rehberde ayrıca yüksek riskli kişilere bakılan bölgelerde konaklayan ve görev yapanların karantina sürelerine de yer verildi. 16.01.2022 08:00 16.01.2022 08:00 Sağlık Bakanlığı karantina ve izolasyon uygulamalarına ilişkin güncellenmiş bir kılavuz yayınladı. Buna göre, COVID-19 kılavuzunun “Temas Takibi, Salgın Yönetimi, Hasta Takibi ve Dosyalama”…
Read More
Index Of News
Total
0
Share