HomeSecurityDDoS attacks measuring tens of terabits: Coming soon

DDoS attacks measuring tens of terabits: Coming soon

Corero Network Security has uncovered a new DDoS attack vector that was first observed targeting its customers last week. The company says the attackers were using a new amplification technique that leverages the Lightweight Directory Access Protocol (LDAP): one of the most widely used protocols for accessing username and password information in databases like Active Directory, which is built into most online servers.

Experts have observed a small number of short but extremely powerful attacks originating from this vector. The new technique has the potential to cause significant damage by using an amplification factor that increases the size of the attacks by 55 times. So in terms of its dynamic scale, if combined with the IoT botnet used in the recent attack against Brian Krebs and Dyn, we could soon see new records in the DDoS attack landscape, as it will have the potential to reach sizes of tens of terabits per second.
DDoS

The DDoS landscape has been extremely volatile in recent weeks, most notably with the release of the Mirai botnet code that can infect IoT devices.

“This new actor could represent a significant escalation in the already dangerous DDoS landscape, with the potential for events that will make recent headline-grabbing attacks seem very small in comparison. When combined with other methods, particularly IoT botnets, we could soon see attacks reaching scales that previously seemed impossible. Terabit-scale attacks could soon become a reality and could significantly impact Internet availability in some regions,” said Dave Larson, CTO/COO of Corero Network Security.

How does the enhanced DDoS attack work?

The attacker sends a simple query to a vulnerable reflector that supports the Connectionless LDAP (CLDAP) service, using the victim's IP address. The CLDAP service responds to the spoofed address, and begins sending unsolicited traffic over the network to the attacker's intended target.

Amplification techniques allow malicious users to amplify the size of their attacks because the responses produced by LDAP servers are much larger than the attacker's queries. In this case, the LDAP service responses are capable of achieving very high bandwidth, so the average amplification factor reaches 46x and during peak hours 55x.

Dave Larson explains:

“LDAP is not the first, nor is it the last, protocol or service that can be exploited in this way. New reinforcement attacks occur frequently because there are so many open services on the Internet that respond to spoofed queries. However, many of these attacks can be mitigated by the service provider by properly identifying spoofed IP addresses before these requests are accepted into the network. In particular, the use of the best common practice, BCP 38, described as Internet Engineering Task Force (IETF) RFC 2827, can eliminate the use of spoofed IP addresses by using effective ingress filtering techniques.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS