Escalating DoS attacks may 'shut down the Internet'

Denial-of-service attacks are growing faster than bandwidth is being added to the Internet, according to VeriSign, the company that administers the .com domain.

Criminal groups selling services online are increasingly threatening the fabric of the Internet, as the size of the compromised networks of computers they control increases, according to VeriSign.

The company claimed that a successful denial-of-service (DoS) attack against VeriSign could bring down the Internet. "There are attacks attempting to shut down our servers," said Ken Silva, VeriSign's chief security officer. "This would effectively shut down the Internet."

Silva said that although DoS attacks are difficult to trace, there are "a couple of well-known groups in Russia, China and Romania" that may be acting with their government's knowledge. "It would be hard to imagine groups who have this much activity going unnoticed by their governments," he said.

The chief security officer said that VeriSign "hoped to get smarter" in blocking malicious traffic. "We can continue to add bandwidth, but ultimately 20 years down the road, this can't continue as a footrace. The Internet as a whole has to get smarter in denying DoS attacks."

VeriSign is currently upgrading its infrastructure in a scheme called Project Titan. This has included adding bandwidth, but it is also monitoring its systems more closely.

"Our monitoring systems now resemble those for the space shuttle," said Silva. "We monitor the capability of our CPUs and memory allocation on all of our servers. We're predicting what problems will occur rather than waiting for them to occur."

Many public-sector organisations in the UK suffer from DoS attacks. The Probation Service has upgraded its servers in the past week to cope with the traffic created by botnets, according to a security manager for the Probation Service.

"We've had to upgrade our hardware in the last week to cope with an unexpected increase in the volume of malicious traffic at the network gateway," the security manager told ZDNet Australia sister site ZDNet.co.uk. "Simply coping with that is compromising our ability to run our business. The problem is simply coping with what is coming at us."

Tim Pickett, a former technical security analyst at AOL, said that ISPs should monitor their networks to mitigate DoS attacks. "ISPs should be monitoring what's going through their networks," said Pickett. "More should be done to tackle the problem on the ISP side."

Advertisement

Talkback 3 comments

    VeriSign Dean -- 26/09/07

    I don't see how, if VeriSign's server went down, it would "effectively shut down the Internet." VeriSign may be the authoritative directory for .com, but DNS is a *distributed* database (heck, that's what the "D" in "DNS" stands for!) which means if you take one node out, the others continue to function.

    Behind the smoke Gavin -- 26/09/07

    Surely you are not suggesting that this is just self important posturing by a US business with a government granted monopoly? Good god, it's unthinkable or, perhaps it's a little dash of sweet self hype from one of the TLD communities finest spin doctors? Don't know, with a change of guard in the whitehouse not too far away, I would be watching anyone who makes a buck out of domain names closely. Expect the number of press releases to rise and the amount of content to fall!

    Behind the smoke Dean -- 26/09/07 (in reply to #320086782)

    Gavin: God forbid! :-)

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured