Showing posts with label Dyn. Show all posts
Showing posts with label Dyn. Show all posts

Friday, October 21, 2016

DDoS attack "breaks" internet for hours

The cloud-based internet company Dyn was the target of a DDoS attack today. (dyn.com)

For over two hours Friday morning, many United States internet users experienced painfully slow internet or had no connection at all. This Internet breakdown wasn't due to Kim K or the new iPhone release but in fact a large-scale Distributed Denial of Service (DDoS) attack on cloud-based Internet performance company Dyn.

The company hosts a variety of domain name systems and many popular sites were brought to a standstill such as The New York Times, Twitter, Pinterest, Reddit, GitHub, Etsy, Tumblr, Spotify, PayPal, Verizon, Comcast, EA, the Playstation network, and others, according to user reports and the web-tracking site downdetector.com.

Steven Morgan, founder of the research firm Cybersecurity Ventures said in an interview the problem is that hackers move much more quickly than cyber-defenders.

"A DDoS attack can be launched in literally seconds, or under an hour if it's coordinated by a larger group," he said. "Right now, we're in the phase of figuring out where did this come from."

Outages like this one have been increasing in occurrence lately.

“Recently, some of the major companies that provide the basic infrastructure that makes the Internet work have seen an increase in DDoS attacks against them,” the security technologist Bruce Schneier wrote in a blog post in September. “Moreover, they have seen a certain profile of attacks. These attacks are significantly larger than the ones they're used to seeing. They last longer. They're more sophisticated. And they look like probing.”

In a statement, Dyn said that this morning, October 21, Dyn received a DDoS attack on its DNS infrastructure on the east coast starting at around 5:10 a.m. MDT.

“DNS traffic resolved from east coast name server locations are experiencing a service interruption during this time. Updates will be posted as information becomes available,” the company wrote.
In an update posted at 6:45 a.m. MDT, the company confirmed the attack, noting that "this attack is mainly impacting US East and is impacting Managed DNS customers in this region. Our Engineers are continuing to work on mitigating this issue."

The Dyn status website posted the following update at 4 p.m. this afternoon:

"On Friday October 21, 2016 at approximately 11:10 UTC, Dyn came under attack by a large Distributed Denial of Service (DDoS) attack against our Managed DNS infrastructure in the US-East region. Customers affected may have seen regional resolution failures in US-East and intermittent spikes in latency globally. Dyn’s engineers were able to successfully mitigate the attack at approximately 13:20 UTC, and shortly after, the attack subsided.
At roughly 15:50 UTC a second DDoS attack began against the Managed DNS platform. This attack was distributed in a more global fashion. Affected customers may have seen intermittent resolution issues as well as increased global latency. At approximately 17:00 UTC, our engineers were again able to mitigate the attack and service was restored.

At Dyn, we take every incident seriously and work hard to ensure we deliver the service our customers have come to expect. We will continue to evaluate every situation with the goal of improving our systems and processes to deliver the utmost customer experience. Thank you for your continued support."