Re: Problems with implementation - DoS attacks possible
Dave Dittrich <[email protected]> Fri, 24 Jan 2003 09:35:27 -0800 (PST)
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 24 Jan 2003, Marcus Leech wrote: > Mikael Olsson wrote: > > > > > > Backbone routers would have to track heaploads of hosts even > > during normal traffic. Maybe they can cope with it, maybe not. > > > > However, small edge routers would have to track heaploads of > > hosts during random source DDoS. Remember that we also send > > tracebacks to the source IPs, so these routers would suddenly have > > to remember all these fake addresses and send key disclosures to > > all of them. > > > A backbone router at 2.8gbits/sec handles (on average) about 1.75 > packets/second. With a probability for ITRACE emission of 1/20,000, > that's 87 ITRACE packets/second. If the key change interval is 1 > minute, and those 87 packets/second were all to different hosts > (which they likely won't be under DDoS conditions), we have to > remember about 5250 IP addresses, or about 160kbytes of memory for > IPV6. I urge that you all keep some numbers and trends in mind from DDoS attacks that have already been waged, so you can better predict what must be handled in the future. In 1999, we were seeing DDoS networks in the high hundreds, to a total (perhaps not all used at once) of 3,000 to 5,000 agents (I *hate* the term "zombies" ;). These attacks were mostly against a single target, or as few as a dozen or so end servers. In 2000, we started seeing attacks against the routing infrastructure itself (e.g., the attack on oz.net in Seattle that happened before RSA 2000), which hit routers in upstream providers Semaphore and UUNet: http://seattlepi.nwsource.com/local/smrf18.shtml This trend has continued, and other attacks have also gone after the infrastructure, rather than flood a single IP address: http://www.techweb.com/wire/story/TWB20010524S0010 I think it is safe to assume that all DDoS agents will not always target a single host, nor that they will all target different hosts, but I can foresee 10,000 hosts attacking 1,000 routers/servers at once, or 100 sets of 1,000 hosts, each set attacking several dozen targets. -- Dave Dittrich Computing & Communications [email protected] University Computing Services http://staff.washington.edu/dittrich University of Washington PGP key http://staff.washington.edu/dittrich/pgpkey.txt Fingerprint FE97 0C57 0843 F3EB 49A1 0CD0 8E0C D0BE C838 CCB5