HomeSecurityDDoS attackers found a new trick to hit sites

DDoS attackers have found a new trick to hit sites

Distributed denial of service (DDoS) attackers are using a new technique to take sites offline by targeting vulnerable "middleboxes," such as firewalls, to amplify junk traffic attacks.

DDoS attackers have found a new trick to hit sites

Amplification attacks are nothing new and have helped attackers bring down servers with brief bursts of traffic of up to 3.47 Tbps. Microsoft last year downplayed attacks of this scale that were the result of competition between online game players.

But there’s a new attack on the horizon. Akamai, a content distribution network company, says it has seen a recent wave of attacks using “TCP Middlebox Reflection,” a reference to the Transmission Control Protocol (TCP) — a founding protocol for secure internet communications between networked machines. The attacks have reached speeds of up to 11 Gbps with 1.5 million packets per second (Mpps), according to Akamai.

The amplification technique was revealed in a research paper last August, which showed that attackers could abuse middleboxes like firewalls over TCP to amplify denial of service. The work came from researchers at the University of Maryland and the University of Colorado Boulder.

Most DDoS attacks abuse the User Datagram Protocol (UDP) to boost packet delivery, sending packets to a server that responds with a larger packet size, which is then forwarded to the attacker's intended target.

The TCP attack exploits network middleboxes that do not comply with the TCP standard. Researchers found hundreds of thousands of IP that could amplify attacks over 100 times using firewalls and content filtering devices.

So, what was a theoretical attack just eight months ago is now a real and active threat.

DDoS attack-minor

Firewalls and similar middlebox devices from Cisco, Fortinet, SonicWall, and Palo Alto Networks are essential pieces of enterprise network infrastructure. However, some middleboxes do not properly validate TCP stream states when enforcing content filtering policies.

Attackers can abuse these frames by spoofing the intended victim's source IP address to direct response traffic from middleboxes.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS