DDoS attackers have found this new trick to knock over websites

Distributed denial of service (DDoS) attackers are using a new technique to knock websites offline by targeting vulnerable ‘middleboxes’, such as firewalls, to amplify junk traffic attacks. 

Amplification attacks are nothing new and have helped attackers knock over servers with short busts of traffic as high as 3.47 Tbps. Microsoft last year mitigated attacks on this scale that were the result of competition between online-gaming players

But there’s a new attack on the horizon. Akamai, a content distribution network firm, says it has seen a recent wave of attacks using “TCP Middlebox Reflection”, referring to transmission control protocol (TCP) – a founding protocol for secured communications on the internet between networked machines. The attacks reached 11 Gbps at 1.5 million packets per second (Mpps), according to Akamai.

SEE: Cybersecurity: Let’s get tactical (ZDNet special report)

The amplification technique was revealed in a research paper last August, which showed that attackers could abuse middleboxes such as firewalls via TCP to magnify denial of service attacks. The paper was from researchers at the University of Maryland and the University of Colorado Boulder.

Most DDoS attacks abuse the User Datagram Protocol (UDP) to amplify packet delivery, generally by sending packets to a server that replies with a larger packet size, which is then forwarded to the attacker’s intended target. 

The TCP attack takes advantage of network middleboxes that don’t comply with the TCP standard. The researchers found hundreds of thousands of IP addresses that could amplify attacks by over 100 times utilizing firewalls and content filtering devices. 

So, what was a theoretical attack just eight months ago is now a real and active threat. 

“Middlebox DDoS amplification is an entirely new type of TCP reflection/amplification attack that is a risk to the internet. This is the first time we’ve observed this technique in the wild,” it says in a blogpost

Firewalls and similar middlebox devices from the likes of Cisco, Fortinet, SonicWall and Palo Alto Networks, are key pieces of corporate network infrastructure. Some middleboxes however don’t properly validate TCP stream states when enforcing content filtering policies. 

“These boxes can be made to respond to out-of-state TCP packets. These responses often include content in their responses meant to “hijack” client browsers in an attempt to prevent users from getting to the blocked content. This broken TCP implementation can in turn be abused to reflect TCP traffic, including data streams, to DDoS victims by attackers,” Akamai notes. 

Attackers can abuse these boxes by spoofing the source IP address of the intended victim to direct response traffic from the middleboxes. 

In TCP, connections use the synchronize (SYN) control flag to exchange key messages for a  three-way handshake. The attackers abuse the TCP implementation in some middelboxes that cause them to unexpectedly respond to SYN packet messages. In some cases, Akamai observed that a single SYN packet with a 33-byte payload produced a 2,156-byte response, amplifying its size by 6,533%.   

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Alipay Raises Transaction Limits for Foreigners: Up to $5000 Per Transaction thumbnail

Alipay Raises Transaction Limits for Foreigners: Up to $5000 Per Transaction

The State Council recently issued the ‘Opinions on Further Optimizing Payment Services to Improve Payment Convenience’, guiding payment service providers to continuously improve the convenience and satisfaction of payment services for elderly people, foreign nationals in China, and other groups. Alipay announced that it actively responds to the relevant decisions and deployments of the Party
Read More
Redmi Note 12 in for review thumbnail

Redmi Note 12 in for review

The Redmi Note 12 series made their European debut earlier this week and now they are marching into our office one by one. Having welcomed the Redmi 12 Pro it’s now time to say 'Hi' to the 5G member of the Redmi Note 12 duo. The Redmi Note 12 5G is only the second smartphone
Read More
California appeals decision regarding Activision Blizzard settlement thumbnail

California appeals decision regarding Activision Blizzard settlement

Activision Blizzard’s legal troubles just took another potential turn. The California Department of Fair Employment and Housing (DFEH) is appealing a judge’s decision that denies it from intervening in the $18 million settlement between the game developer and the US Equal Employment Opportunity Commission (EEOC), according to a document filed Friday. Activision Blizzard and the…
Read More
A ‘constant merry-go-round’: Nielsen and Comscore say the right things, but aren’t progressing fast enough for media buyers thumbnail

A ‘constant merry-go-round’: Nielsen and Comscore say the right things, but aren’t progressing fast enough for media buyers

September 30, 2021 by Michael Bürgi The move to planning and buying television nationally on an impressions basis rather than on ratings has been relatively smooth and steady over the last two years. But local buying and planning has been a bit of a messier story, especially in light of recent issues around Nielsen’s pandemic-related…
Read More
Best snow blower of 2024 thumbnail

Best snow blower of 2024

Most of the US is experiencing cold temperatures and blizzards as over half of the country is covered in snow and winter weather advisories go into effect. If you've been using that 10-year-old snow blower of yours amid this snowy weather and realizing it's no longer up to par, it might be time to pick up
Read More
Index Of News
Total
0
Share