A new wave of cyberattacks has been detected, surprising not only in duration but also in intensity. What seemed impossible a couple of years ago has now happened: a DDoS capable of surpassing the terabit-per-second mark. How can those responsible amass such firepower? Essentially, through botnets that combine exposed cameras, compromised routers, and an Internet of Things that is very weak in terms of security.

New DDoS Attack Breaks the Terabit per Second Barrier
DDoS

A Record-Breaking Attack on Krebs On Security

Two weeks ago, the renowned security portal Krebs On Security fell victim to an unprecedented DDoS attack. Estimates speak of 620 gigabits per second, and according to Akamai, the company protecting Krebs On Security, it was nearly twice as large as the most intense attack previously recorded. The duration of the assault put Brian Krebs in serious trouble, leaving him no choice but to take the site offline for 24 hours. In the process, Akamai could not continue absorbing the associated costs (Krebs is a pro bono client), and direct competitors asked him for hundreds of thousands of dollars per year. In the end, Krebs' site was protected by Google's Project Shield, and many concluded that "someone was burning their botnet," so a period of silence was expected... however, a few days later an even larger attack would emerge.

New DDoS Attack Breaks the Terabit per Second Barrier
Cameras exposed to the Web, recording systems and vulnerable routers are part of the army carrying out these massive DDoS attacks.

OVH Under Fire

The victim this time was the French connectivity provider OVH. According to its founder and CTO Octave Klaba, on September 19, 2016 the company suffered two massive impacts, with a DDoS of 1.1 terabits per second, and immediately after, another of 901 gigabits per second. Last Friday, Klaba reported additional attacks, with similar intensity (800 Gbps). The most interesting part is that he also provided details about the type of devices behind the attacks: closed-circuit cameras exposed to the Web, DVRs, and vulnerable routers. Klaba indicated that the attack on OVH and Krebs On Security would have been the work of the same botnet, but believe it or not, that's not the point. What really worries is that the DDoS of the future will manage to deploy such intensity "on average," and not as the last gasp of a botnet about to fall.

The Future of DDoS

Martin McKeay of Akamai believes the situation will be like that. Not all attacks will reach that mark, but he estimates that "dozens" will be observed per quarter, until reaching "several hundred" within a year, which translates into theoretical blackouts that could affect a provider, or an entire region in the worst case. The only thing we can do is verify that the security on our devices is correctly configured, change factory passwords on modems and/or routers, and if possible, disconnect them. That's not viable in the case of a router, but it's not unreasonable to think that our generic surveillance cameras are another cartridge in the arsenal of these chilling cannons.

Source: