All the latest UK technology news, reviews and analysis

Icann shield beats DNS hackers

by Clement James

12 Mar 2007

Be the first to comment

  • Tweet this
Icann
Icann claims that the internet withstood a major attack because of the Anycast shield technology

The Internet Corporation for Assigned Names and Numbers (Icann) has released a report on the well publicised attack on the internet's backbone of DNS servers early in February.

The report indicates that the internet withstood the attack because of the Anycast shield technology implemented after the last attack of a significant size in 2002.

The 13 core DNS servers of the internet were hit with a significant distributed denial of service attack in early February originating from the Asia-Pacific region.

Six of the 13 root servers that form the foundation of the internet were affected. The two worst affected did not have Anycast installed, Icann said, highlighting the effectiveness of the load balancing technology.

"Even though it was a large attack, the new technology, combined with the speed, skills and experience learned by root server operators over the years, helped to make sure that actual internet users were not inconvenienced," Icann said.

Anycast allows a number of servers in different places to act as if they are in the same location.

While there are 13 locations on the network for root servers, the reality on the ground is that not only are there often dozens at one spot but dozens of servers in other locations that can also deal with requests.

In the case of the F-root, for example, there are no fewer than 42 different locations supporting the root server.

Following the start of the attack in February, engineers soon discovered that all the attack packets were larger than 512-bytes and were able simply to block any packets larger than this size.

With the Anycast technology apparently proven, it is likely that the remaining D, E, G, H and L roots will move over soon, Icann said.

Interestingly, while the motive for the attack remains largely unknown, Icann suggested that it could have been an advertisement for a particular botnet, demonstrating how much power it had at its disposal.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Java Developer - Belfast - Banking

Java Developer - Belfast - Banking Skills: Core Java...

Shared Accounting Service Manager - London

I am recruiting for a Shared Accounting Service Manager...

QA Tester/Automation Tester - C# .NET Agile, Epsom

QA Tester/Automation Tester - C# .NET Agile, Epsom, Surrey...

3RD LINE EXCHANGE 2010 / 2003, QUEST, LONDON, BLUE CHIP FIRM, CITY

3RD LINE EXCHANGE 2010 / 2003, QUEST, LONDON, GLOBAL...

To send to more than one email address, simply separate each address with a comma.